Persistent fault analysis method based on voltage burrs
By acquiring the chip's offline data and voltage glitch parameter clusters, offline voltage glitch injection and fault data acquisition are carried out, which solves the problems of low efficiency, high cost and contingency in the existing technology, and achieves efficient and accurate fault analysis.
Patent Information
- Application Number
- CN202510866581.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-26
- Publication Date
- 2025-08-05
AI Technical Summary
Existing fault analysis methods rely on transient faults, resulting in low analysis efficiency, high cost and highly contingent results, and inability to make full use of other types of faults.
By obtaining offline data of the sample chip, determining the voltage glitch parameter cluster, and performing voltage glitch injection in offline state, obtaining fault collection data for continuous fault analysis, ensuring coverage of all possible glitch conditions and improving testing efficiency and coverage.
It achieves rapid and accurate evaluation of the chip's persistent fault resistance, finds out vulnerabilities, reduces testing costs, and improves the efficiency of fault analysis and the universality of test results.
Smart Images

Figure CN120428077A_ABST
Abstract
Description
Technical Field
[0001] The present application belongs to the field of chip testing technology, and in particular relates to a method for analyzing persistent faults based on voltage glitches. Background Art
[0002] With the growing demand for information security, integrated circuits and security chips have been widely used in various applications, such as smart cards, payment terminals, and encryption devices. However, these security chips face various physical attack threats, including voltage fault injection (VFI) attacks, a common type of fault analysis attack. Attackers briefly glitches the chip's power supply voltage during operation, disrupting its normal operation and attempting to cause it to produce erroneous outputs or leak sensitive information.
[0003] Existing fault analysis methods, such as differential fault analysis, are mostly based on transient faults. These methods have three problems: First, they cannot fully utilize other types of faults, resulting in low analysis efficiency and the need to collect a large amount of data; second, transient fault-based fault analysis requires continuous application of faults while the chip is operating normally (i.e., online), which places high demands on the openness of the test samples and also leads to high costs for chip fault analysis and testing; third, due to the characteristics of transient faults such as power failure or reset loss, transient fault analysis test results are difficult to repeat and compare, resulting in accidental analysis and lack of authority. Summary of the Invention
[0004] The embodiment of the present application provides a method for continuous fault analysis based on voltage glitches, which can solve the problems of low fault analysis efficiency, high testing cost and accidental analysis results caused by reliance on transient faults for analysis during the fault analysis process.
[0005] In a first aspect, an embodiment of the present application provides a method for analyzing a persistent fault based on voltage glitches, comprising: Obtain offline data of sample chips; Determining a voltage glitch parameter cluster corresponding to the sample chip according to the offline data of the sample chip, and controlling a glitch injection device to perform voltage glitch injection on the sample chip in an offline state based on the voltage glitch parameter cluster; Acquiring fault collection data of the sample chip; wherein the fault collection data is fault data collected when the sample chip is powered on and after voltage glitch injection; Performing continuous fault analysis on the sample chip based on the fault collection data to determine a sample analysis result of the sample chip.
[0006] The above technical solutions in the embodiments of the present application have at least the following technical effects: The method for analyzing persistent faults based on voltage glitches provided in the embodiment of the present application provides basic data for the subsequent determination of voltage glitch parameter clusters by acquiring offline data of sample chips. According to the offline data of the sample chip, the voltage glitch parameter cluster corresponding to the sample chip is determined to ensure that all possible glitch conditions are covered within a limited time, thereby improving test efficiency and coverage, and controlling the glitch injection device to inject voltage glitches into the sample chip in an offline state based on the voltage glitch parameter cluster, thereby providing a precondition for subsequent fault data collection. The fault collection data of the sample chip is obtained, and the abnormal data generated when the collection chip is running under a simulated fault environment is collected to provide a core basis for performing persistent fault analysis. Based on the fault collection data, a persistent fault analysis is performed on the sample chip to determine the sample analysis results of the sample chip, thereby achieving a rapid and accurate assessment of the chip's persistent fault resistance capability, and finding the vulnerable points of the sample chip under different conditions, thereby providing a scientific basis for improving chip design and optimizing protective measures, improving fault analysis efficiency, reducing testing costs, and improving the universality of test results.
[0007] In a second aspect, an embodiment of the present application provides a system for analyzing persistent faults based on voltage glitches, including: An acquisition unit, used for acquiring offline data of a sample chip; a parameter unit, configured to determine a voltage glitch parameter cluster corresponding to the sample chip according to the offline data of the sample chip, and control a glitch injection device to perform voltage glitch injection on the sample chip in an offline state based on the voltage glitch parameter cluster; A data unit, configured to obtain fault collection data of the sample chip; wherein the fault collection data is fault data collected when the sample chip is powered on and after voltage glitch injection; The result unit is configured to perform continuous fault analysis on the sample chip based on the fault collection data, and determine a sample analysis result of the sample chip.
[0008] In a third aspect, an embodiment of the present application provides an electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the method described in any one of the above aspects when executing the computer program.
[0009] In a fourth aspect, an embodiment of the present application provides a computer program product, which, when executed on an electronic device, enables the electronic device to execute the method according to any one of the above aspects.
[0010] It can be understood that the beneficial effects of the second to fourth aspects mentioned above can be found in the relevant descriptions of the above aspects and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the embodiments or descriptions of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0012] Figure 1 This is a flow chart of a method for analyzing a persistent fault based on voltage glitches provided in one embodiment of the present application; Figure 2 This is a schematic diagram of the operation of a method for analyzing a continuous fault based on voltage glitches provided by an embodiment of the present application; Figure 3 This is a schematic diagram of the operation of a method for analyzing a continuous fault based on voltage glitches provided by an embodiment of the present application; Figure 4 This is a schematic diagram of the operation of a method for analyzing a continuous fault based on voltage glitches provided by an embodiment of the present application; Figure 5 This is a partial schematic diagram of a continuous fault analysis system based on voltage glitch provided by an embodiment of the present application. Figure 6 It is a structural diagram of an electronic device provided in one embodiment of the present application. DETAILED DESCRIPTION
[0013] In the following description, specific details such as specific system structures and techniques are provided for purposes of illustration rather than limitation to facilitate a thorough understanding of the embodiments of the present application. However, it will be apparent to those skilled in the art that the present application may be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid obscuring the description of the present application with unnecessary detail.
[0014] It should be understood that when used in the present specification and the appended claims, the term "comprising" indicates the presence of described features, integers, steps, operations, elements and / or components, but does not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or collections thereof.
[0015] It will also be understood that the term "and / or" used in this specification and the appended claims refers to and includes any and all possible combinations of one or more of the associated listed items.
[0016] As used in this specification and the appended claims, the term "if" can be interpreted as "when" or "upon" or "in response to determining" or "in response to detecting," depending on the context. Similarly, the phrases "if it is determined" or "if the described condition or event is detected" can be interpreted as meaning "upon determination" or "in response to determining" or "upon detection of the described condition or event" or "in response to detecting the described condition or event," depending on the context.
[0017] In addition, in the description of the present application specification and the appended claims, the terms "first", "second", "third", etc. are only used to distinguish the descriptions and cannot be understood as indicating or implying relative importance.
[0018] References to "one embodiment" or "some embodiments" in this specification mean that a particular feature, structure, or characteristic described in conjunction with that embodiment is included in one or more embodiments of the present application. Thus, phrases such as "in one embodiment," "in some embodiments," "in other embodiments," and "in other embodiments" appearing in various places in this specification do not necessarily refer to the same embodiment, but rather mean "one or more but not all embodiments," unless otherwise specifically emphasized. The terms "including," "comprising," "having," and variations thereof all mean "including but not limited to," unless otherwise specifically emphasized.
[0019] Existing fault analysis methods, such as differential fault analysis, are based on transient faults. These methods suffer from three problems: First, they cannot fully utilize other types of faults, resulting in low analysis efficiency and the need to collect a large amount of data; second, transient fault-based fault analysis requires continuous application of faults while the chip is operating normally (i.e., online), which places high demands on the openness of the test samples and leads to high costs for chip fault analysis and testing; third, transient faults, due to their power-off or reset loss characteristics, make transient fault analysis test results difficult to repeat and compare, resulting in accidental analysis and lack of authority.
[0020] To solve the above problems, an embodiment of the present application provides a method for continuous fault analysis based on voltage glitches. In this method, by obtaining offline data of a sample chip, basic data is provided for the subsequent determination of a voltage glitch parameter cluster. Based on the offline data of the sample chip, the voltage glitch parameter cluster corresponding to the sample chip is determined to ensure that all possible glitch conditions are covered within a limited time, thereby improving test efficiency and coverage, and based on the voltage glitch parameter cluster, the glitch injection device is controlled to inject voltage glitches into the sample chip in an offline state, providing a precondition for subsequent fault data collection. The fault collection data of the sample chip is obtained, and the abnormal data generated when the collection chip is running in a simulated fault environment is collected to provide a core basis for continuous fault analysis. Based on the fault collection data, a continuous fault analysis is performed on the sample chip to determine the sample analysis results of the sample chip, thereby achieving a rapid and accurate assessment of the chip's continuous fault resistance capability, and finding the vulnerable points of the sample chip under different conditions, thereby providing a scientific basis for the improvement of chip design and the optimization of protective measures, improving fault analysis efficiency, reducing testing costs, and improving the universality of test results.
[0021] The method for analyzing a continuous fault based on voltage glitches provided in the embodiment of the present application can be applied to electronic devices. In this case, the electronic device is the executor of the method for analyzing a continuous fault based on voltage glitches provided in the embodiment of the present application. The embodiment of the present application does not impose any restrictions on the specific type of electronic device.
[0022] For example, the electronic device may be an ultra-mobile personal computer (UMPC), a netbook, a desktop computer, a computer, a laptop computer, a communication device, a computing device, a satellite wireless device, etc.
[0023] In order to better understand the method for analyzing a continuous fault based on voltage glitches provided in an embodiment of the present application, the specific implementation process of the method for analyzing a continuous fault based on voltage glitches provided in an embodiment of the present application is exemplarily introduced below.
[0024] Figure 1 FIG2 shows a schematic flow chart of a method for analyzing a persistent fault based on voltage glitches provided in an embodiment of the present application. Figure 2 The following is a schematic diagram showing the operation of a method for analyzing a persistent fault based on voltage glitches provided in an embodiment of the present application. The method for analyzing a persistent fault based on voltage glitches includes: S100, obtaining offline data of a sample chip.
[0025] Understandably, acquiring offline data from sample chips is fundamental to the entire fault analysis process. Offline data typically contains information about the chip's original operating parameters, circuit characteristics, and logic state before fault injection. This information includes, for example, the chip's supply voltage range, clock frequency, the default levels of each pin, and the initial values of internal registers. This data can be collected in a variety of ways: by connecting a chip test fixture to the chip's debug interface (such as JTAG or SWD) and using dedicated test software to read the chip's internally stored configuration information; by using a logic analyzer to capture the chip's signal waveform in real time when no load is applied; or by using the development tool chain provided by the chip manufacturer to derive factory default parameters from the chip's non-volatile memory (such as Flash or EEPROM). Offline data provides a baseline for subsequent analysis of the chip's fault susceptibility and determination of fault injection parameters.
[0026] S200 , determining a voltage glitch parameter cluster corresponding to the sample chip according to offline data of the sample chip, and controlling a glitch injection device to perform voltage glitch injection on the sample chip in an offline state based on the voltage glitch parameter cluster.
[0027] It is understandable that after analyzing offline data, a series of characteristic parameter combinations related to voltage glitches can be determined, such as the voltage mutation threshold that the chip can withstand and the sensitive operating frequency band. This collection of characteristic parameter combinations constitutes a voltage glitch parameter cluster, which includes dimensions such as amplitude, frequency, and duration. Subsequently, an automated script can be used to control the glitch injection device (such as an arbitrary waveform generator or pulse signal source) to generate specific voltage glitch signals based on the parameter cluster, and then apply them to the chip's designated pins or power lines through a probe station or dedicated interface. For example, if offline data shows that the chip's transient immunity on the 5V power line is ±10%, then the voltage glitch parameter cluster can include a collection of multiple voltage glitch signals with amplitudes of 4.5V-5.5V and durations of 10ns. By simulating voltage anomalies in a real environment, the chip is forced into a fault state, creating conditions for subsequent fault data collection.
[0028] In a possible implementation, in step S200, determining a voltage glitch parameter cluster corresponding to the sample chip based on offline data of the sample chip includes: S210 , determining a voltage glitch characteristic index corresponding to the sample chip according to offline data of the sample chip.
[0029] As you can understand, voltage glitch characteristic indicators are key parameters extracted from offline data of sample chips, used to characterize the chip's sensitivity and response to voltage glitches. This can be achieved through in-depth analysis of offline data. For example, using chip design documents and simulation models to obtain basic parameters such as the chip's internal circuit voltage tolerance and signal transmission delay. Static current testing (IDDQ testing) can be used to analyze the chip's current fluctuations under no-load conditions to identify nodes sensitive to voltage anomalies. A spectrum analyzer can be used to measure the frequency domain characteristics of the chip's clock and data bus signals to identify frequency bands susceptible to interference. Feature extraction from offline data, such as principal component analysis (PCA) dimensionality reduction, can be performed to identify core voltage parameters that affect chip stability. Parameters extracted from offline data of sample chips, such as power supply voltage fluctuation threshold and signal edge time tolerance, together constitute voltage glitch characteristic indicators, providing a basis for subsequent fault event retrieval, similar to determining mechanical property indicators from stress-strain curves in material testing.
[0030] S220 , searching a fault event archive for a fault event including at least one voltage glitch characteristic indicator based on the voltage glitch characteristic indicator to obtain a plurality of fault events to be selected.
[0031] It can be understood that the fault event archive is a pre-built database that stores historical records of faults of different chip models under various voltage glitch conditions. Each record contains the voltage glitch parameters that caused the fault, the fault phenomenon, and the analysis conclusion. The retrieval process can be implemented using a data matching algorithm, using voltage glitch characteristic indicators (such as amplitude threshold and frequency range) as search keywords, and performing fuzzy matching or exact matching in the fault event archive through SQL query statements or search engines such as Elasticsearch. For example, if the characteristic indicators show that the chip is sensitive to voltage amplitudes above 5.5V, all fault events involving amplitudes greater than 5.5V in the fault event archive are retrieved; if there are multiple characteristic indicators (such as amplitude and frequency combinations), a logical "OR" operation is used to expand the search scope to ensure that all possible related events are covered.
[0032] S230 , filtering out voltage glitch characteristic indicators contained in each candidate fault event to obtain a plurality of supplementary fault data.
[0033] It's understandable that additional valid information can be extracted from candidate fault events to avoid reusing established characteristic indicators. Each candidate fault event can be processed using a data cleansing algorithm. Regular expressions or data parsing tools can be used to identify and remove parameter fields in the event record that overlap with the voltage glitch characteristic indicators (such as the established amplitude threshold). The remaining parameters (such as glitch duration, location, and accompanying environmental conditions) are standardized to a unified data format. For example, if a candidate event record states "amplitude 6V, frequency 200MHz, duration 30ns, resulting in register flip," and 6V is already included in the characteristic indicators, the amplitude parameter can be filtered out, while the frequency, duration, and fault phenomenon are retained as supplementary fault data.
[0034] S240 , determining a voltage glitch parameter cluster corresponding to the sample chip based on the multiple candidate fault events and the multiple supplementary fault data.
[0035] It can be understood that the known characteristic indicators in the selected fault events can be integrated with the supplementary data to form a data set containing multi-dimensional parameters (such as amplitude, frequency, duration, fault type, etc.), and the parameter combination that is most likely to cause chip failure can be extracted through data mining algorithms.
[0036] Optionally, S240, determining a voltage glitch parameter cluster corresponding to a sample chip based on a plurality of candidate fault events and a plurality of supplementary fault data, includes: S241 , clustering is performed based on a plurality of candidate fault events and a plurality of supplementary fault data to obtain a plurality of fault data clusters.
[0037] As you can understand, clustering uses K-means and hierarchical clustering to group similar candidate fault events and supplementary fault data to identify common parameter patterns. All events leading to chip logic errors can be grouped into clusters based on parameter similarity, potentially containing combinations of glitches with different amplitudes but the same frequency. During the clustering process, metrics such as Euclidean distance and Manhattan distance can be calculated to map high-dimensional data points into a low-dimensional space, forming statistically significant clusters.
[0038] S242 , calculating the degree of aggregation of each fault data cluster, and screening out the fault data clusters whose degree of aggregation meets a predetermined threshold; wherein the degree of aggregation is calculated based on the proportion of the same fault feature in each candidate fault event and the supplementary fault data.
[0039] As you can understand, the degree of aggregation is used to assess the reliability and representativeness of clusters, reflecting the closeness of the data within the cluster. The number of occurrences of the same fault signature (such as register flips and bus errors) in each cluster across all candidate fault events and supplementary faults can be counted, divided by the total number of events within the cluster to obtain the proportion, and then a weighted sum is taken to generate the degree of aggregation. For example, if 80% of the events in a cluster result in the same type of register error, the degree of aggregation is high, indicating that the parameter combination in the cluster is strongly correlated with the fault. A predetermined threshold (such as 70%) is used to filter out noisy clusters to ensure that the retained clusters are of practical analytical value.
[0040] Exemplarily, S242, calculating the degree of aggregation of each fault data cluster, and screening out the fault data clusters whose degree of aggregation meets a predetermined threshold, includes: S2421 , obtaining the occurrence frequency of the same fault feature in each fault data cluster in each candidate fault event and supplementary fault data.
[0041] As you can understand, the prevalence of fault characteristics can be statistically quantified. All candidate fault events and supplementary fault data within each cluster are traversed. Using fault characteristics (such as "memory bit flip" and "logic gate false trigger") as keys, a hash table is constructed to count their occurrence frequencies. For example, if "memory bit flip" appears in 120 records in a cluster containing 200 records, its frequency is 60%. Parallel computing frameworks (such as Spark) can be used to accelerate processing and provide real-time data support for subsequent weight calculations.
[0042] S2422: Calculate the weight value of each fault feature based on the occurrence frequency.
[0043] It can be understood that the weight value can be dynamically calculated through the information gain algorithm to reflect the ability of fault features to distinguish clusters. , where information gain is calculated by feature The change in cluster purity before and after the introduction (such as the reduction in the Gini coefficient) is obtained, and f' represents any feature in the feature set F, which is used to calculate the sum of the information gain of all features. For example, a feature The introduction of reduces the cluster's Gini coefficient from 0.5 to 0.3, resulting in an information gain of 0.2, accounting for 40% of the total information gain and corresponding to a weight of 0.4. The information gain algorithm can automatically suppress high-frequency but low-discrimination features (such as ubiquitous power supply fluctuations) and highlight key fault characteristics (such as specific register anomalies).
[0044] S2423 , calculating the aggregation degree of each fault data cluster according to the weight value, and screening out the fault data clusters whose aggregation degree meets a predetermined threshold; the aggregation degree is the weighted sum of the weight values of each fault feature.
[0045] It can be understood that the aggregation degree calculation can be achieved by vector dot product, and the weight vector of the fault feature is dot-producted with the frequency vector to obtain the aggregation degree of each cluster. , frequency vector , then the degree of polymerization is When screening, the heap sort algorithm is used to quickly locate clusters with a degree of aggregation ≥ 0.7, with a time complexity of 0(n )(k is the number of clusters screened).
[0046] S243 , determining a voltage glitch parameter cluster corresponding to the sample chip according to the screened fault data clusters.
[0047] It can be understood that the fault data clustering clusters screened out by the parameter space fusion algorithm can be used to determine the voltage glitch parameter cluster corresponding to the sample chip. For each screened cluster, the statistical characteristics of its parameters (mean, variance, and confidence interval) are calculated. A parameter similarity matrix is constructed, and the similarity of parameters between clusters is evaluated using cosine similarity. Similar clusters are merged to generate parameter ranges (such as amplitude 5.5±0.2V and frequency 150±10MHz). Constrained optimization is performed using the sample chip's process parameters (such as power supply noise tolerance and clock jitter range) to ultimately determine the voltage glitch parameter cluster, ensuring that the voltage glitch parameter cluster is based on historical fault data and conforms to the physical characteristics of the current chip.
[0048] Exemplarily, S243, determining a voltage glitch parameter cluster corresponding to the sample chip based on the screened fault data clusters, includes: S2431 , creating a feature vector space for each screened fault data cluster, and determining the probability density distribution of the fault feature map in each fault data cluster in the feature vector space.
[0049] It can be understood that fault characteristics can be quantitatively analyzed by constructing a high-dimensional feature space. Fault characteristics (such as glitch amplitude, frequency, and duration) can be vectorized to form an n-dimensional feature vector (n is the number of features). Principal component analysis (PCA) is used to reduce the dimensionality of the original features, extracting principal components with a cumulative contribution rate of 95% to form a new vector space, effectively eliminating multicollinearity between features. In the feature vector space, the kernel density estimation (KDE) method is used to generate a probability density distribution. The kernel function can be a Gaussian kernel, and the bandwidth parameter is determined through cross-validation to ensure the accuracy of the distribution estimation. For example, for the amplitude characteristics of a cluster, the probability density distribution curve generated by KDE can intuitively display the probability of occurrence of different amplitude ranges, providing a statistical basis for the subsequent determination of parameter clusters.
[0050] S2432: applying a unitary matrix transformation to each eigenvector space, and determining the characteristic coupling degree between different fault data clusters through statistical correlation.
[0051] As you can understand, unitary matrix transformation is an important operation in linear algebra. In the context of voltage glitch parameter analysis, unitary matrix transformation can be used to reveal hidden correlations between different fault data clusters. Its core function is to make the statistical characteristics of the data easier to analyze by rotating or reflecting the vector space. Unitary matrix transformation is implemented using singular value decomposition (SVD), which decomposes the characteristic matrix into the product of three matrices: ,in and is a unitary matrix. By rotating the vector space, the statistical characteristics of the data are easier to analyze. The characteristic coupling degree is calculated using canonical correlation analysis (CCA), and the characteristic vectors of the two clusters can be expressed as and , and then solve the generalized eigenvalue problem , where λ is the eigenvalue, a is the corresponding eigenvector, and the maximum eigenvalue is obtained , the coupling degree is defined as ,The value range is [0,1]. The larger the value, the stronger the coupling. For example, if the coupling degree of two clusters is 0.85, it means that their fault characteristics have a high degree of synergy and may be caused by the same type of voltage glitches.
[0052] S2433: construct a joint probability distribution function based on the characteristic coupling degree and perform marginalization processing on the joint probability distribution function to determine the voltage glitch parameter cluster corresponding to the sample chip.
[0053] As can be understood, a joint probability distribution function (JPDF) is a probabilistic model that describes the simultaneous occurrence of multiple random variables (such as the amplitude, frequency, and duration of a voltage spike). It can reveal the dependencies and synergies between these variables. The JPDF can be constructed using a Gaussian mixture model (GMM), with model parameters estimated using the expectation-maximization (EM) algorithm. The GMM parameters (mean, covariance matrix, and mixing coefficient) are initialized, and then the E-step (calculating the posterior probability that each data point belongs to each Gaussian component) and the M-step (updating the model parameters and maximizing the log-likelihood function) are alternately performed until convergence. Marginalization is achieved by integrating the unrelated variables of the joint distribution. For example, to obtain the marginal distribution of the amplitude parameter, the frequency and duration variables are integrated. A 95% confidence interval is extracted from the marginal distribution as the parameter cluster value range to ensure that the parameters cover the majority of possible fault-causing conditions. The JPDF can also be constructed using a vine copula model, which can flexibly capture nonlinear dependencies between variables. Each fault feature can be transformed into a uniform distribution through a probability integral transformation. An appropriate Copula function (such as Clayton or Gumbel) is selected based on the feature coupling. A vine structure is constructed, and the dependency hierarchy between variables is determined through conditional independence tests. Copula parameters are estimated and optimized using the maximum likelihood method. Marginalization is achieved through conditional decomposition of the vine copula model. For example, when calculating (P(X|Y=y)), the conditional density formula of the copula is used to derive the probability distribution function. A probability distribution function accurately describes the probability distribution of other features (such as amplitude) given the known value of a particular feature (such as frequency).
[0054] Exemplarily, S2433, constructing a joint probability distribution function based on the characteristic coupling degree and performing marginalization processing on the joint probability distribution function to determine a voltage glitch parameter cluster corresponding to the sample chip, includes: S24331: Construct a joint probability distribution function based on the feature coupling degree, perform marginalization on the superimposed distribution function, and determine the conditional probability distribution of each fault feature.
[0055] It can be understood that the joint probability distribution function is constructed by using the Gaussian mixture model (GMM), treating each fault data cluster as a Gaussian component, and the characteristic coupling is reflected by the covariance matrix. For example, if the coupling degree between amplitude and frequency is 0.7, the corresponding covariance matrix element is ( 、 The Gaussian distributions of all clusters can be linearly superimposed according to the mixing coefficient to form a joint distribution covering all samples. By integrating to eliminate irrelevant variables, such as calculating the conditional probability amplitude frequency When the duration and other characteristics are integrated, the conditional distribution curve related only to the amplitude is obtained.
[0056] S24332, mapping the conditional probability distribution to the voltage glitch parameter space and generating the probability density function of the voltage glitch parameter cluster by the maximum entropy principle.
[0057] It is understandable that the abstract probability value of the conditional probability distribution can be converted into actual physical parameters (such as a continuous interval of amplitude from 0V to 10V) using the quantile mapping method. For example, the probability 0.025 is mapped to the lower limit of the amplitude and 0.975 is mapped to the upper limit. Under known constraints (such as mean and variance), the distribution with the largest entropy can be selected as the probability density function. For example, if the only known amplitude mean is 5.5V and the variance is 0.25, then the maximum entropy distribution is the Gaussian distribution. , achieving unbiased distribution and covering all possibilities.
[0058] S24333: Perform expectation maximization estimation on the probability density function and extract the maximum likelihood parameter combination as the voltage glitch parameter cluster corresponding to the sample chip.
[0059] It is understood that the parameters of the probability density function can be optimized iteratively. For example, for a Gaussian mixture model, the EM algorithm can estimate the mean, variance, and mixing coefficient of each component to maximize the model's fit to the data. The parameter point with the largest probability density can be extracted from the optimized distribution, such as the mean of the Gaussian distribution. This is the maximum likelihood estimate. For multi-parameter combinations (such as amplitude 5.5V, frequency 150MHz, and duration 20ns), this combination has the highest probability density in the joint distribution and is most likely to cause chip failure. Through probabilistic modeling and optimization algorithms, discrete fault data is converted into precisely controllable voltage glitch parameters, achieving a closed loop of "data-driven—probabilistic modeling—parameter derivation." For example, the extracted voltage glitch parameter cluster can be directly input into an arbitrary waveform generator to generate a glitch sequence that meets the 95% confidence interval, achieving fault injection coverage and repeatability, enabling rapid and accurate assessment of the chip's ability to resist persistent faults. This covers a wider range of voltage glitch parameter combinations in a short period of time, identifying its vulnerabilities under different conditions, and avoiding the inefficiency of manually setting parameters in traditional methods, thereby providing a scientific basis for improving chip design and optimizing protective measures.
[0060] In a possible implementation, in step S200, controlling a glitch injection device to perform voltage glitch injection on a sample chip in an offline state based on a voltage glitch parameter cluster includes: S250 , performing decoupling based on the voltage glitch parameter cluster to generate a time-series voltage glitch sequence corresponding to the voltage glitch parameter cluster.
[0061] It can be understood that the statistical characteristics of a voltage glitch parameter cluster can be converted into an executable time-domain waveform, and the mapping from the probabilistic model to the physical signal can be achieved through parameter decoupling and time-series reconstruction. The voltage glitch parameter cluster (such as amplitude, frequency, and duration) can be decoupled to eliminate the coupling relationship between the parameters (for example, by converting the covariance matrix into a diagonal matrix through Cholesky decomposition). Subsequently, random sampling points are generated based on the marginal probability distribution of the parameters. The probability values are mapped to physical parameters through inverse transform sampling. A time-series voltage glitch sequence is generated using a time-series reconstruction algorithm (such as an ARIMA model or a deep learning network), ensuring that the statistical characteristics of the sequence (such as mean and variance) are consistent with the original parameter cluster.
[0062] S260 , controlling a glitch injection device to perform voltage glitch injection on a sample chip in an offline state according to a time-series voltage glitch sequence.
[0063] It can be understood that fault injection verification can be achieved through hardware control, converting the generated timing voltage glitch sequence into control instructions (such as SCPI commands) that comply with the glitch injection device interface specification. The instructions contain waveform parameters (amplitude, frequency), trigger conditions (such as clock edges), and injection duration. When the sample chip is placed in an offline state (i.e., powered off but the test fixture remains connected), the digital sequence is converted into an analog voltage glitch through a high-precision DAC (digital-to-analog converter) and injected into specific pins of the chip (such as power, clock, or data bus) through a probe or PCB trace. During the injection process, the injection moment and the precise waveform are synchronously recorded to ensure that the experiment is repeatable. The voltage glitch application occurs in an offline state, which can ensure a long time to adjust the voltage glitch parameters and implement the injection.
[0064] S300, acquiring fault collection data of a sample chip; wherein the fault collection data is fault data collected when the sample chip is powered on and working after voltage glitch injection.
[0065] It is understood that after the voltage glitch injection is completed, the chip can be powered on and benchmark test programs (such as memory read and write tests and logic function verification) can be run. The electrical signals of key nodes of the chip (such as power supply ripple, clock jitter, and bus data) can be monitored in real time using a multi-channel high-speed oscilloscope or logic analyzer, and the internal register status can be collected and saved through the on-chip debugging interface (such as JTAG and SWD). Figure 3 When an anomaly is detected (such as a program error or data error), the data capture mechanism is triggered to record waveform data, register snapshots, and system status before and after the fault occurs. Fault diagnosis information (such as error code and occurrence timestamp) is obtained in real time through the serial port (UART) or USB interface.
[0066] Before acquiring the fault collection data of the sample chip, the method further includes: S500: Determine the fault type of the sample chip.
[0067] It is understandable that a preliminary fault injection test is conducted on the sample chip to observe the time characteristics and triggering conditions of the fault phenomenon. By applying a single voltage glitch and monitoring the chip response, if the fault recovers immediately after the glitch disappears, it is determined to be a transient fault; if the fault persists and is not affected by subsequent glitches, it is determined to be a persistent fault; if the fault occurs periodically or at random intervals, it is determined to be an intermittent fault. The fault type can be further assisted by analyzing the internal register status of the chip, such as whether the program counter (PC) jumps to an illegal address or whether a fixed bit flip occurs in the memory. For example, if a storage unit always returns an incorrect value in multiple tests, it can be determined to be a fixed-type fault within a persistent fault.
[0068] S600: When the fault type of the sample chip is a persistent fault, collect fault data of the sample chip in a powered-on state.
[0069] As you can understand, after confirming the fault type, the chip remains powered on and benchmark tests (such as cyclic checksum calculations and bus communication tests) are run. Simultaneously, critical signals are captured in real time using hardware monitoring equipment (such as logic analyzers and oscilloscopes). Since persistent faults persist while the chip is powered on, continuous acquisition mode can be used to record the complete waveform of the fault signal at a fixed sampling rate (such as 1 GS / s). Alternatively, triggered acquisition mode can be used to automatically save data from a period of time when specific fault characteristics (such as activation of the data bus error flag) are detected. During acquisition, contextual information such as the fault occurrence timestamp, chip operating frequency, and ambient temperature are simultaneously recorded, providing multi-dimensional data support for subsequent analysis. For example, when acquiring persistent memory bit flip faults, address bus signals can be simultaneously monitored to locate the address range of the faulty memory cells. This combined offline and online fault analysis approach allows voltage glitch application to occur offline, ensuring a longer time to adjust voltage glitch parameters and perform injection. The actual analysis and data acquisition occurs online, requiring only a small amount of data to complete the analysis, thus reducing overall test time and optimizing test implementation conditions. Chip failures caused by voltage glitches will be saved in the firmware, ensuring the standardization and consistency of each test process, greatly improving the accuracy and reliability of the test results, and at the same time ensuring the repeatability of the test, making the results under different test conditions comparable.
[0070] S400 , performing continuous fault analysis on the sample chip based on the fault collection data, and determining a sample analysis result of the sample chip.
[0071] It's understandable that chip fault data can be analyzed from collected fault data to draw diagnostic and instructive conclusions. By applying cryptographic analysis methods and statistical techniques, combined with information such as the distribution characteristics of ciphertext in the fault data and chip response characteristics, the impact of persistent faults on the chip's operational logic can be analyzed to locate the root cause of the fault. For example, for cryptographic chips, ciphertext anomalies caused by the fault can be analyzed to infer key information or operational unit errors. Ultimately, sample analysis results covering the fault type, impact range, and potential repair directions can be output, providing a basis for chip design improvements or fault repair.
[0072] In one possible implementation, S400, performing continuous fault analysis on the sample chip based on the fault collection data to determine the sample analysis result of the sample chip, includes: S410 , performing ciphertext frequency analysis on the sample chip based on the fault collection data, and determining a ciphertext byte set that does not appear in the fault collection data.
[0073] It's understandable that frequency analysis principles from cryptography can be used to quantify and count the ciphertext bytes in the fault data. The occurrences of all ciphertext bytes can be counted, and the frequency of each ciphertext byte in the fault data can be calculated. Since the ciphertext output by a cryptographic algorithm should normally exhibit a nearly uniform distribution, by comparing the actual frequency with this uniform distribution, it's possible to identify ciphertext bytes with abnormally low or even zero frequencies. These ciphertext bytes constitute the set of missing ciphertext bytes. Abnormal bytes are often associated with computational errors caused by persistent chip failures and provide key clues for subsequently deducing the cause of the failure.
[0074] For example, the ciphertext output byte stream can be extracted from the fault data collection, excluding interference data generated by non-cryptographic operations (such as protocol headers and check bits). The occurrences of ciphertext bytes (0x00-0xFF, a total of 256 possible values) are counted, and the frequency of each ciphertext byte is calculated (frequency = number of occurrences / total number of samples). This is compared to the normal ciphertext distribution (an ideal uniform distribution, with a byte frequency of approximately 1 / 256 ≈ 0.39%), and bytes with significantly deviating frequencies, particularly bytes with a frequency of zero, are screened out.
[0075] Exemplarily, S410, performing ciphertext frequency analysis on the sample chip based on the fault collection data to determine a ciphertext byte set that does not appear in the fault collection data, includes: S411 , performing ciphertext frequency analysis on the sample chip based on the fault collection data to obtain a ciphertext byte frequency distribution histogram corresponding to the fault collection data.
[0076] As you can understand, visualization can be used to directly visualize ciphertext distribution characteristics. Using tools like Matplotlib and Excel, a histogram can be created, with the horizontal axis showing the ciphertext byte values (0x00-0xFF) and the vertical axis showing the frequency (percentage or count). For example, if 10,000 ciphertext records are collected and a byte c appears 0 times, its frequency is 0%, and it will appear as a column of zero height in the histogram. Normal bytes have a frequency of approximately 1%, and the columns have uniform heights. Histograms can be used to quickly locate abnormal bytes and help determine whether the fault has a measurable impact on cryptographic operations.
[0077] S412: Extract a first ciphertext byte set with a zero occurrence frequency according to the ciphertext byte frequency distribution histogram.
[0078] As can be understood, by traversing the histogram and recording all bytes with a frequency of zero, the first ciphertext byte set is formed. For example, if it is detected that 5 bytes (0x1A, 0x3F, 0x7B, 0x9D, 0xE2) do not appear in 10,000 ciphertexts, the set is {0x1A, 0x3F, 0x7B, 0x9D, 0xE2}.
[0079] S413 , performing a hypothesis test on the first ciphertext byte set to screen out all ciphertext bytes that significantly deviate from the random distribution, obtaining a second ciphertext byte set that does not appear in the fault collection data, and determining the second ciphertext byte set as the ciphertext byte set that does not appear in the fault collection data.
[0080] It is understandable that a frequency of zero may be caused by random fluctuations (especially when the sample size is small), and the reliability needs to be verified through subsequent hypothesis testing. Statistical hypothesis testing can be used to exclude accidental factors, and the null hypothesis can be used to verify the reliability of the hypothesis. Assume that the ciphertext byte distribution is uniform random distribution. Through the chi-square test ( Test), calculate the statistic: ,in is the observation frequency, Total number of samples is the expected frequency. The degrees of freedom are set to 255 (256 bytes - 1). The significance level is =0.05, look up the table to get the critical value If the calculated value > critical value, reject , the distribution is considered non-random. For each byte in the first ciphertext byte set, if its absence leads to a significant increase in the chi-square statistic (i.e., p-value < 0.05), it is retained as the second ciphertext byte set.
[0081] S420 , performing reverse calculation based on the ciphertext byte set that does not appear in the fault collection data to determine the sample analysis result of the sample chip.
[0082] It can be understood that after counting the ciphertext C that does not appear in the fault collection data, the key of a single S box can be reversed. Figure 4 Taking the AES algorithm as an example, let the single-byte S-box output of the last round of the algorithm be P[0], and the first byte of the round key K[0] of the last round be XORed to obtain the first byte of the output ciphertext C[0], which satisfies the following formula: , due to the existence of persistent faults, the value of P[0] cannot be p. Therefore, when enough C[0] is collected, the ciphertext byte c that cannot appear in C[0] is obtained. According to the formula: The first byte of the last round key can be deduced, and the process is repeated 16 times to obtain the complete round key of the last round. The master key or complete round key can be reversed to form a sample analysis result containing the fault location, key information or algorithm vulnerabilities, providing a key basis for chip security assessment or physical attack defense, completing continuous fault analysis, and realizing a rapid and accurate assessment of the chip's continuous fault resistance capability, identifying the vulnerabilities of the sample chip under different conditions, thereby providing a scientific basis for improving chip design and optimizing protective measures.
[0083] Corresponding to the method for analyzing a persistent fault based on voltage glitches in the above embodiment, an embodiment of the present application further provides a system for analyzing a persistent fault based on voltage glitches, and each unit of the system can implement each step of the method for analyzing a persistent fault based on voltage glitches. Figure 5 A structural block diagram of a continuous fault analysis system based on voltage glitches provided in an embodiment of the present application is shown. For ease of explanation, only the parts related to the embodiment of the present application are shown.
[0084] Reference Figure 5 The voltage glitch-based continuous fault analysis system includes: An acquisition unit, used for acquiring offline data of a sample chip; a parameter unit, configured to determine a voltage glitch parameter cluster corresponding to the sample chip according to the offline data of the sample chip, and control a glitch injection device to perform voltage glitch injection on the sample chip in an offline state based on the voltage glitch parameter cluster; A data unit, configured to obtain fault collection data of the sample chip; wherein the fault collection data is fault data collected when the sample chip is powered on and after voltage glitch injection; The result unit is configured to perform continuous fault analysis on the sample chip based on the fault collection data, and determine a sample analysis result of the sample chip.
[0085] It should be noted that the information interaction, execution process, etc. between the above-mentioned systems / units are based on the same concept as the method embodiment of this application. Their specific functions and technical effects can be found in the method embodiment section and will not be repeated here.
[0086] Those skilled in the art can clearly understand that, for the convenience and brevity of description, only the division of the above-mentioned functional units and modules is used as an example for illustration. In actual applications, the above-mentioned functions can be distributed and completed by different functional units and modules as needed, that is, the internal structure of the system can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiment can be integrated into one processing unit, or each unit module can exist physically alone, or two or more unit modules can be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of software functional units. In addition, the specific names of the functional units and modules are only for the convenience of distinguishing each other and are not used to limit the scope of protection of this application. The specific working process of the units and modules in the above-mentioned system can refer to the corresponding process in the aforementioned method embodiment, which will not be repeated here.
[0087] The embodiment of the present application also provides an electronic device, Figure 6 This is a schematic diagram of the structure of an electronic device provided in one embodiment of the present application. Figure 6 As shown, the electronic device 6 of this embodiment includes: at least one processor 60 ( Figure 6 Only one is shown), at least one memory 61 ( Figure 6 Only one is shown in the figure) and a computer program 62 stored in the at least one memory 61 and executable on the at least one processor 60. When the processor 60 executes the computer program 62, the electronic device 6 implements the steps of any of the above-mentioned embodiments of the method for analyzing continuous faults based on voltage glitches, or implements the functions of the units in the above-mentioned system embodiments.
[0088] For example, the computer program 62 may be divided into one or more units, which are stored in the memory 61 and executed by the processor 60 to implement the present application. The one or more units may be a series of computer program instruction segments capable of implementing specific functions, and the instruction segments are used to describe the execution process of the computer program 62 in the electronic device 6.
[0089] The electronic device 6 can be a computing device or terminal device such as a desktop computer, a notebook, a PDA, or a cloud server. The electronic device may include, but is not limited to, a processor 60 and a memory 61. Those skilled in the art will understand that Figure 6It is only an example of the electronic device 6 and does not constitute a limitation on the electronic device 6. It may include more or fewer components than shown in the figure, or a combination of certain components, or different components. For example, it may also include input and output devices, network access devices, buses, etc.
[0090] The processor 60 may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor.
[0091] In some embodiments, the memory 61 may be an internal storage unit of the electronic device 6, such as a hard drive or memory of the electronic device 6. In other embodiments, the memory 61 may also be an external storage device of the electronic device 6, such as a plug-in hard drive, a Smart Media Card (SMC), a Secure Digital (SD) card, a flash memory card, etc. equipped on the electronic device 6. Furthermore, the memory 61 may include both an internal storage unit of the electronic device 6 and an external storage device. The memory 61 is used to store an operating system, application programs, a boot loader, data, and other programs, such as the program code of the computer program. The memory 61 may also be used to temporarily store data that has been output or is about to be output.
[0092] An embodiment of the present application further provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps in any of the above method embodiments are implemented.
[0093] An embodiment of the present application provides a computer program product. When the computer program product is run on an electronic device, the electronic device implements the steps of any of the above method embodiments.
[0094] If the integrated unit is implemented as a software functional unit and sold or used as a standalone product, it can be stored in a computer-readable storage medium. Based on this understanding, the present application implements all or part of the process steps in the above-mentioned method embodiments by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When executed by a processor, the computer program can implement the steps of each of the above-mentioned method embodiments. The computer program includes computer program code, which can be in source code form, object code form, executable file, or some intermediate form. The computer-readable medium can include at least: any entity or device capable of carrying computer program code to an electronic device, recording medium, computer memory, read-only memory (ROM), random access memory (RAM), electric carrier signals, telecommunication signals, and software distribution media. Examples include USB flash drives, removable hard drives, magnetic disks, or optical disks. In some jurisdictions, based on legislation and patent practice, computer-readable media cannot be electric carrier signals or telecommunication signals.
[0095] In the above embodiments, the description of each embodiment has its own focus. For parts that are not described or recorded in detail in a certain embodiment, reference can be made to the relevant description of other embodiments.
[0096] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0097] In the embodiments provided in the present application, it should be understood that the disclosed system / electronic device and method for continuous fault analysis based on voltage glitches can be implemented in other ways. For example, the above-described embodiment of the system / electronic device for continuous fault analysis based on voltage glitches is merely illustrative. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.
[0098] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0099] The above-described embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present application, and should all be included in the scope of protection of the present application.
Claims
1. A method for analyzing persistent faults based on voltage glitches, characterized in that: include: Obtain offline data of sample chips; Determining a voltage glitch parameter cluster corresponding to the sample chip according to the offline data of the sample chip, and controlling a glitch injection device to perform voltage glitch injection on the sample chip in an offline state based on the voltage glitch parameter cluster; Acquiring fault collection data of the sample chip; wherein the fault collection data is fault data collected when the sample chip is powered on and after voltage glitch injection; A continuous fault analysis is performed on the sample chip based on the fault collection data to determine a sample analysis result of the sample chip.
2. The method for analyzing persistent faults based on voltage glitches according to claim 1, wherein: Determining, according to the offline data of the sample chip, a voltage glitch parameter cluster corresponding to the sample chip, comprising: Determining a voltage glitch characteristic index corresponding to the sample chip according to the offline data of the sample chip; Based on the voltage glitch characteristic index, searching a fault event archive for a fault event that includes at least one of the voltage glitch characteristic indicators to obtain a plurality of fault events to be selected; Filtering out the voltage glitch characteristic index contained in each of the selected fault events to obtain a plurality of supplementary fault data; Based on the plurality of candidate fault events and the plurality of supplementary fault data, a voltage glitch parameter cluster corresponding to the sample chip is determined.
3. The method for analyzing persistent faults based on voltage glitches according to claim 2, wherein: Determining a voltage glitch parameter cluster corresponding to the sample chip based on the plurality of candidate fault events and the plurality of supplementary fault data includes: Clustering the plurality of selected fault events and the plurality of supplementary fault data to obtain a plurality of fault data clusters; Calculating the degree of aggregation of each of the fault data clusters, and screening out the fault data clusters whose degree of aggregation meets a predetermined threshold; wherein the degree of aggregation is calculated based on the proportion of the same fault feature in each of the candidate fault events and the supplementary fault data; The voltage glitch parameter cluster corresponding to the sample chip is determined according to the screened fault data cluster.
4. The method for analyzing persistent faults based on voltage glitches according to claim 3, wherein: The calculating the aggregation degree of each of the fault data clusters and screening out the fault data clusters whose aggregation degree meets a predetermined threshold comprises: Obtain the occurrence frequency of the same fault feature in each fault data cluster in each candidate fault event and supplementary fault data; Calculating a weight value of each fault feature based on the occurrence frequency; The aggregation degree of each fault data cluster is calculated according to the weight value, and the fault data clusters whose aggregation degree meets a predetermined threshold are screened out; the aggregation degree is the weighted sum of the weight values of each fault feature.
5. The method for analyzing persistent faults based on voltage glitches according to claim 3, wherein: The step of determining the voltage glitch parameter cluster corresponding to the sample chip based on the filtered fault data clusters includes: Creating a feature vector space for each of the fault data clusters that have been screened out, and determining a probability density distribution of the fault feature map in each of the fault data clusters in the feature vector space; Applying a unitary matrix transformation to each of the characteristic vector spaces, and determining the characteristic coupling degree between different fault data clusters through statistical correlation; A joint probability distribution function is constructed based on the characteristic coupling degree and marginalization is performed on the joint probability distribution function to determine a voltage glitch parameter cluster corresponding to the sample chip.
6. The method for analyzing persistent faults based on voltage glitches according to claim 5, wherein: The step of constructing a joint probability distribution function based on the characteristic coupling degree and performing marginalization processing on the joint probability distribution function to determine a voltage glitch parameter cluster corresponding to the sample chip includes: Constructing a joint probability distribution function based on the feature coupling degree, performing marginalization processing on the superimposed distribution function, and determining the conditional probability distribution of each of the fault features; Mapping the conditional probability distribution to the voltage glitch parameter space and generating a probability density function of the voltage glitch parameter cluster by the maximum entropy principle; An expectation maximization estimation is performed on the probability density function, and a maximum likelihood parameter combination is extracted as a voltage glitch parameter cluster corresponding to the sample chip.
7. The method for analyzing persistent faults based on voltage glitches according to claim 1, wherein: Controlling a glitch injection device to perform voltage glitch injection on the sample chip in an offline state based on the voltage glitch parameter cluster includes: Decoupling is performed based on the voltage glitch parameter cluster to generate a timing voltage glitch sequence corresponding to the voltage glitch parameter cluster; A glitch injection device is controlled according to the timing voltage glitch sequence to perform voltage glitch injection on the sample chip in an offline state.
8. The method for analyzing persistent faults based on voltage glitches according to claim 1, wherein: Before acquiring the fault collection data of the sample chip, the method further includes: determining a fault type of the sample chip; When the fault type of the sample chip is a persistent fault, fault data of the sample chip is collected in a powered-on state.
9. The method for analyzing persistent faults based on voltage glitches according to claim 1, wherein: The performing continuous fault analysis on the sample chip based on the fault collection data to determine the sample analysis result of the sample chip includes: Performing ciphertext frequency analysis on the sample chip based on the fault collection data to determine a ciphertext byte set that does not appear in the fault collection data; A reverse calculation is performed based on the ciphertext byte set that does not appear in the fault collection data to determine the sample analysis result of the sample chip.
10. The method for analyzing persistent faults based on voltage glitches according to claim 9, wherein: The performing ciphertext frequency analysis on the sample chip based on the fault collection data to determine a ciphertext byte set that does not appear in the fault collection data includes: Performing ciphertext frequency analysis on the sample chip based on the fault collection data to obtain a ciphertext byte frequency distribution histogram corresponding to the fault collection data; Extracting a first ciphertext byte set having a zero occurrence frequency according to the ciphertext byte frequency distribution histogram; A hypothesis test is performed on the first ciphertext byte set to screen all ciphertext bytes that significantly deviate from a random distribution, to obtain a second ciphertext byte set that does not appear in the fault collection data, and the second ciphertext byte set is determined as the ciphertext byte set that does not appear in the fault collection data.
Citation Information
Cited By
Electronic lock dynamic risk self-adaptive lock control method based on AI
CN120995316A
AI-based electronic lock dynamic risk self-adaptive lock control method
CN120995316B
Anti-radiation soft error analysis method for AES encryption circuit based on CVPI
CN121562515A
Anti-radiation soft error analysis method based on CVPI facing AES encryption circuit
CN121562515B