Automatic verification of hardware cryptographic implementation
Through an automated tool-driven framework, the data path and control signal verification of hardware password implementation are simplified, solving the time-consuming problem of verification code development in the existing technology and achieving fast and effective hardware password verification.
Patent Information
- Application Number
- CN202480020574.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-03-29
- Filing Date
- 2024-02-14
- Publication Date
- 2025-10-24
AI Technical Summary
Existing technologies have difficulty in effectively verifying the interoperability of the data processing and control parts of hardware cryptographic implementations, resulting in time-consuming and complex verification code development and difficulty in modeling in a verification environment.
This paper provides an automated tool-driven framework that simplifies the data path and control signal verification process of hardware cryptographic implementations by receiving reference implementations and test case data of cryptographic algorithms, generating stimuli, and verifying them using simulation models.
It reduces the development and verification time of hardware cryptographic components, provides a compiled library of cryptographic reference models for reuse, and reduces the technical requirements of verification engineers.
Smart Images

Figure CN120836030A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The field of the present disclosure is data processing, or, more specifically, methods, apparatus, and products for performing automatic verification of hardware cryptographic implementations. BACKGROUND
[0002] The development of the EDVAC computer system of 1948 is often cited as the beginning of the computer era. Since then, computer systems have evolved into extremely sophisticated devices. Today's computers are much more complex than early systems such as the EDVAC. Computer systems typically include a combination of hardware and software components, application programs, operating systems, processors, buses, memory, input / output devices, etc. As semiconductor processing and computer architecture advances push the performance of computers higher, more complex computer software has evolved to take advantage of the higher performance hardware, resulting in today's computer systems that are much more powerful than just a few years ago.
[0003] Cryptography allows secure communication between computing systems. Implementation of cryptographic designs in hardware has allowed acceleration of cryptographic processes. Hardware cryptographic designs are typically implemented using electronic design automation (EDA) software tools that allow for the design of integrated circuits for implementing cryptographic functions. However, cryptographic algorithms are not as easily modeled as other computing operations. Cryptographic algorithms are complex multi-cycle algorithms, and implementations that run thousands of clock cycles before generating a final result are not uncommon. Cryptographic designs include a data processing portion and a control portion. The design of the data processing portion depends on the cryptographic algorithm to be implemented and the PD timing / area challenges. The design of the control portion has higher dependencies on access registers (ARs), millcode, and other hardware units. Hardware implementation of cryptographic algorithms requires ordering of complex algorithms and are difficult to model in a verification environment to check internal states from time to time. Furthermore, developing a verification code for cryptographic features is very time consuming as the data and control portions must be designed to properly interoperate. SUMMARY
[0004] In one aspect of the present invention, a method for automatic verification of hardware cryptographic implementations is provided, the method comprising: receiving a reference implementation of a cryptographic algorithm; receiving test case data associated with the cryptographic algorithm; generating stimuli based on the test case data; applying the stimuli to the reference implementation using a simulation model to generate a first intermediate state result; applying the stimuli to a hardware implementation of the cryptographic algorithm using the simulation model to generate a second intermediate state result; and generating a verification result based on a comparison of the first intermediate state result and the second intermediate state result.
[0005] In another aspect of the application, there is provided an apparatus for automatic verification of hardware cryptographic implementations, the apparatus comprising: a computer processor; and a computer memory operably coupled to the computer processor, the computer memory having computer program instructions disposed within it which, when executed by the computer processor, cause the apparatus to: receive a reference implementation of a cryptographic algorithm; receive test case data associated with the cryptographic algorithm; generate a stimulus based on the test case data; apply the stimulus to the reference implementation using a simulation model to generate a first intermediate state result; apply the stimulus to a hardware implementation of the cryptographic algorithm using the simulation model to generate a second intermediate state result; and generate a verification result based on a comparison of the first intermediate state result and the second intermediate state result.
[0006] In another aspect of the application, there is provided a computer program product disposed on a computer readable medium, the computer program product comprising computer program instructions which, when executed, cause a computer to: receive a reference implementation of a cryptographic algorithm; receive test case data associated with the cryptographic algorithm; generate a stimulus based on the test case data; apply the stimulus to the reference implementation using a simulation model to generate a first intermediate state result; apply the stimulus to a hardware implementation of the cryptographic algorithm using the simulation model to generate a second intermediate state result; and generate a verification result based on a comparison of the first intermediate state result and the second intermediate state result.
[0007] The foregoing and other objects, features and advantages of the present disclosure will be apparent to those skilled in the art in view of the following more particular description of exemplary embodiments of the disclosure, as illustrated in the accompanying drawings, wherein like reference numerals generally designate like parts throughout. BRIEF DESCRIPTION OF DRAWINGS
[0008] Figure 1 A block diagram illustrating an example computing system configured for automatic verification of hardware cryptographic implementations according to embodiments of the present disclosure.
[0009] Figure 2 A block diagram illustrating a cryptographic compilation hardware environment for automatic verification of hardware cryptographic compilation implementations according to embodiments of the present disclosure.
[0010] Figure 3 A flow diagram of an example method for data path verification of hardware cryptographic implementations according to some embodiments of the present disclosure.
[0011] Figure 4 A block diagram illustrating an example process for data path verification of hardware cryptographic compilation implementations according to some embodiments of the present disclosure.
[0012] Figure 5is a flow chart of an example method for hardware cryptographically implemented control signal verification according to some embodiments of the present disclosure.
[0013] Figure 6 A block diagram illustrating an example process flow for automatic verification of hardware password implementations according to an embodiment of the present disclosure is shown.
[0014] Figure 7 is a flow chart of another example method for automatic verification of hardware password implementation according to an embodiment of the present disclosure.
[0015] Figure 8 is a flow chart of another example method for automatic verification of hardware password implementation according to an embodiment of the present disclosure. DETAILED DESCRIPTION
[0016] from Figure 1 Initially, exemplary apparatuses and systems for automatic verification of hardware password implementations according to the present disclosure are described with reference to the accompanying drawings. Figure 1 Set forth is a block diagram of automated computing machinery including an exemplary computing system 100 configured for hardware cryptographically implemented automated authentication, in accordance with an embodiment of the present disclosure. Figure 1 Computing system 100 includes at least one computer processor 110 or “CPU” and random access memory (“RAM”) 120 connected to processor 110 and to other components of computing system 100 through a high-speed memory bus 113 and a bus adapter 112 .
[0017] Stored in RAM 120 is an operating system 122. Operating systems useful in computers configured for hardware cryptographically enabled automatic authentication according to embodiments of the present disclosure include UNIX™, Linux™, Microsoft Windows™, AIX™, and others as will occur to those skilled in the art. Figure 1 In the example of FIG. 1 , operating system 122 is shown as being in RAM 120, but many components of such software are typically also stored in non-volatile memory, such as, for example, on a data storage device 132 (such as a disk drive). Also stored in RAM is a cryptographic hardware design application 124, including software for designing and implementing cryptographic hardware, such as hardware cryptographic implementation 150 according to embodiments of the present disclosure, and automatic verification of hardware cryptographic implementation 150. In certain embodiments, the hardware cryptographic implementation includes an integrated circuit configured to implement a cryptographic algorithm (such as a cryptographic standard). In one or more embodiments, verification of hardware cryptographic implementation 150 includes verifying that hardware cryptographic implementation 150 correctly implements the cryptographic algorithm.
[0018] Figure 1The exemplary computing system 100 includes a disk drive adapter 130 that couples to the processor 110 through a bus 117 and bus adapter 112 and to other components of the computing system 100. The disk drive adapter 130 connects to a nonvolatile data storage, such as a data storage device 132, to the computing system 100. Disk drive adapters useful in computers configured for inserting serial numbers into editable tables in accordance with embodiments of the present disclosure include integrated drive electronics ("IDE") adapters, small computer system interface ("SCSI") adapters, and other adapters as will occur to those of skill in the art. Nonvolatile computer memory can also be implemented as a floppy disk drive, a compact disk drive, an electrically-erasable programmable read-only memory (so-called "EEPROM" or "Flash" memory), a RAM drive, and others as will occur to those of skill in the art.
[0019] Figure 1 The exemplary computing system 100 includes one or more input / output ("I / O") adapters 116. I / O adapters implement user-oriented input / output through, for example, software drivers and computer hardware for controlling the output to display devices such as computer display screens, as well as user input such as keyboards and mice. Figure 1 The exemplary computing system 100 includes a video adapter 134, which is an example of an I / O adapter specially designed for graphic output to a display device 136, such as a display screen or computer monitor. Video adapter 134 is connected to processor 110 through high-speed video bus 115, bus adapter 112, and front side bus 111, which is also a high-speed bus.
[0020] Figure 1 The exemplary computing system 100 includes a communications adapter 114 to enable data communications with other computers and devices. Such communications can be carried out through an RS-232 connection, through an external bus such as a Universal Serial Bus ("USB"), through a data communications network, and in other ways as will occur to those of skill in the art. Communications adapters implement the hardware level of data communications through which one computer sends data communications to another computer, directly or through a data communications network. Examples of communications adapters useful in computers configured for inserting serial numbers into editable tables in accordance with embodiments of the present disclosure include modems for wired dial-up communications, Ethernet (IEEE 802.3) adapters for wired data communications, and 802.11 adapters for wireless data communications. Figure 1 Communications adapter 114 of the computing system 100 is communicatively coupled to a wide area network 140, which further includes other computing devices, such as Figure 1The illustrated server 141. The server 141 is in communication with a reference implementation code and test case data repository 142 that stores reference implementation code for implementing a particular cryptographic algorithm and test case data for testing the correct operation of the cryptographic algorithm.
[0021] As previously mentioned, a cryptographic design includes a data processing portion and a control portion. The design of the data processing portion depends on the cryptographic algorithm to be implemented and the PD timing / area challenge. The design of the control portion has a higher dependency on access registers (ARs), mill code, and other hardware units. It is very time consuming to develop a verification code for a cryptographic feature because the data and control portions must be designed to properly interoperate. For overall verification of a hardware cryptographic implementation that includes various control signals, a simulation environment is used.
[0022] One or more embodiments provide an automated tool-driven framework that allows for easy verification of the data path of a hardware cryptographic implementation as well as an automated process of generating a verification reference model to facilitate easy reuse and accelerated time-to-marked of a hardware cryptographic implementation. One or more embodiments include a two-part process, where the first part includes data path verification and the second part includes control signal verification. In the first part of the process according to one or more embodiments, a user selects a cryptographic algorithm for which reference implementation and test case data is available. In a particular embodiment, the cryptographic algorithm is a National Institute of Standards and Technology (NIST) standard. In an embodiment, an electronic design automation (EDA) tool downloads test case data associated with the cryptographic algorithm, such as known answer test (KAT) data and Monte Carlo test (MCT) data. The EDA tool generates a scenario / stimulus file that is automatically populated according to the cryptographic algorithm, which includes all tests that loop through the test case data. In this embodiment, the user opens the scenario file and enters the facility / signal names for the stimulus input, output, and the number of cycles for computation. In this embodiment, the user runs a simulation, where the scenario file is used to provide input from the test case data (e.g., KAT / MCT data) and the results are automatically checked for validity. As a result, data path verification of the hardware implementation of the cryptographic algorithm is completed.
[0023] In the second part of the process according to embodiments, the EDA tool imports a reference model, such as a cryptographic algorithm provided by a reference subject, and the reference model is compiled into a library file (e.g., a.so or.a file). The library file is included in various test environments that use an application programming interface (API) to perform cryptographic operations. In embodiments, a user selects a cryptographic algorithm to be implemented in a hardware cryptographic implementation, such as a NIST standard cryptographic algorithm. The EDA tool downloads the reference implementation code, creates a wrapper file with the API to call the core functions of the reference implementation code. The EDA tool runs test case data (e.g., KAT and MCT) on the compiled object code and validates that the compiled object code passes the tests based on the test case data. If the compiled object code passes the tests, the EDA tool compiles the code into a library and provides include files for reuse of the library. A verification engineer can then use the reference doe and only use any modification control signals required to test the hardware cryptographic implementation.
[0024] Various embodiments described herein provide that the designer provides a mapping between the internal state (e.g., data + valid) to the function / variable of the reference library implementation. This can be used to easily generate test cases that not only have output expectations for the entire cryptographic operation, but also for the internal or intermediate states of the algorithm. The benefit provided by this approach is that the verification engineer can focus only on creating randomized test cases, rather than spending time understanding and checking the internal state of the hardware. Furthermore, the designer is able to quickly determine the root cause of a failure, rather than having to backtrack a failure run to find the first point of mismatch.
[0025] Figure 2A block diagram of a cryptographic hardware design environment 200 for automatic verification of hardware cryptographic implementation is shown, in accordance with embodiments of the present disclosure. The cryptographic hardware design environment 200 includes a design-level simulation 202 that includes a data processing component 204. The cryptographic hardware design environment 200 includes user controls 206 for allowing a user to control aspects of the design-level simulation 202. The data processing component 204 is configured to perform functions of the design-level simulation, including verifying hardware implementations of cryptographic algorithms as described herein with respect to various embodiments. In one or more embodiments, the cryptographic hardware design environment 200 allows for execution of cryptographic data flows and execution of tests with test case data such as NIST KAT and MCT. In particular embodiments, the cryptographic hardware design environment 200 is configured to allow for downloading of test case data (e.g., KAT / MCT), isolating data flow portions for testing in a designer-level verification framework, creating design-level verification scenarios / stimuli from the test case data, and running the tests and verification results. In particular embodiments, the creation of scenarios / stimuli and the running of tests / verifications are performed automatically for all test case data. In one or more embodiments, the cryptographic hardware design environment allows for control flow changes and simulation to test and emphasize corner cases such as large data, small data, and checkpoint settings.
[0026] To further explain, Figure 3 A flowchart of an example method 300 for data path verification of hardware cryptographic implementations, in accordance with some embodiments of the present disclosure, is set forth. The method 300 includes selecting 302 a cryptographic algorithm that is a NIST standard using EDA tools, and downloading 304 KAT and MCT test case data from the NIST standard repository. The method 300 also includes generating 306 scenarios / stimuli that are automatically populated according to the cryptographic algorithm, and looping this generation over all tests.
[0027] The method 300 also includes selecting 308 facilities / signal names for stimulus inputs, stimulus outputs, and number of cycles to use from the computation within the simulation. The method 300 also includes running 310 the simulation, where the scenarios are used to provide inputs from the KAT / MCT test data, and automatically checking the validity of the results. Upon confirming the validity of the test results, the data path verification of the hardware implementation of the cryptographic algorithm is complete 312.
[0028] In particular embodiments, user parameterizable configurations include selection of cryptographic reference code and test cases, configuration of input of valid signals, configuration of input of data signals, configuration of ratio of input data width to operation data width for multi-cycle inputs, configuration of output valid signals, or number of clock cycles for simulation operation to complete, and configuration of output data signals. In one or more embodiments, test case scenarios are automatically generated based on the configurations, and the test cases are run to provide a summary of results.
[0029] Figure 4 A block diagram illustrating an example process 400 of hardware cryptographic implementation data path verification according to some embodiments of the present disclosure. In the example process 400, a user specifies a netlist 402 that specifies the data path of a hardware cryptographic implementation. From the netlist 402, a test case scenario 404 is created. Once the test case scenario 404 is run on a simulation, an analysis 406 of each test is generated.
[0030] Figure 5 A flowchart of an example method 500 for control signal verification of a hardware cryptographic implementation according to some embodiments of the present disclosure is set forth. The method 500 includes a user selecting 502 a cryptographic algorithm that is a NIST standard using an EDA tool. The EDA tool downloads 504 the NIST reference implementation code for the cryptographic algorithm from the NIST standard repository.
[0031] The EDA tool then creates 506 a wrapper file with an API to call the core functions of the cryptographic algorithm by compiling the reference implementation code. The EDA tool then runs 508 KAT and MCT test case data on the compiled object and verifies that the compiled object passes the test cases. The EDA tool conforms 510 the code into a library and provides include files for reusing the library. Thus, the reference model provided by the NIST standard is imported and compiled into a library file, such as a.so or.a file.
[0032] The verification engineer then uses 512 the reference code and only modifies any control signals needed to test the cryptographic hardware implementation. Thus, the library can be included in various test environments that use the API to perform cryptographic operations to test the cryptographic hardware implementation.
[0033] To further explain, Figure 6 A block diagram of an example process flow 600 for automatic verification of a hardware cryptographic implementation according to embodiments of the present disclosure is set forth. In a traditional process for verifying a hardware cryptographic implementation, a verification engineer studies the cryptographic standard in order to understand the cryptographic algorithm, studies the reference code, and integrates the reference code into a verification environment (e.g., an RTX verification environment). The verification engineer then creates a list of hardware facilities to drive randomized data into the hardware simulation model and expected outputs. The verification engineer then generates the randomized data and uses the reference model to calculate the expected results. The verification engineer then runs the test cases and analyzes the results.
[0034] According to example process flow 600, a design engineer runs an EDA tool to generate test cases from a reference model 606 of a cryptographic algorithm, and the EDA tool generates a list of hardware facilities 602 that can be used in a verification environment. The EDA tool imports source code (e.g., C / C++ files) from the reference implementation into the verification environment. The EDA tool automatically generates monitor code 608 configured to monitor input hardware facilities driven by a driver 604 into the reference model 606 and a hardware simulation model 610. The EDA tool installs monitor events to compute expected outputs when the input facilities are triggered. The EDA tool automatically generates monitor code that compares the reference computation results with the results observed on the output facilities of the hardware simulation model 610. A verification engineer can review the automatically generated files and modify the verification environment to drive randomized data into the hardware simulation model 610. The verification engineer can then run the test cases and analyze the results to determine whether the hardware cryptographic implementation is verified.
[0035] To further explain, Figure 7 A flowchart of another example method 700 for automatic verification of a hardware cryptographic implementation according to embodiments of the present disclosure is set forth. The method 700 includes receiving 702 a reference implementation of a cryptographic algorithm, and receiving 704 test case data associated with the cryptographic algorithm. In particular embodiments, the cryptographic algorithm is associated with a cryptographic standard, such as a NIST standard. In particular embodiments, the test case data includes KAT and MCT test case data. In particular embodiments, the reference implementation of the cryptographic algorithm and the test case data are retrieved from a reference standard repository. The method further includes generating 706 stimuli based on the test case data.
[0036] The method 700 further includes applying 708 the stimuli to the reference implementation using a simulation model to generate first intermediate state results, and applying 710 the stimuli to a hardware implementation of the cryptographic algorithm using the simulation model to generate second intermediate state results. In particular embodiments, the respective intermediate state results are output signals of the simulated intermediate states. The method 700 further includes generating a verification result based on a comparison of the first intermediate state results and the second intermediate state results. In particular embodiments, the hardware cryptographic implementation is determined to be verified if the verification result determines that the first intermediate state results are substantially equivalent to the second intermediate state results.
[0037] In embodiments, the method 700 further includes determining expected output signals of the hardware implementation based on the test case data and the reference implementation. In embodiments, generating 712 the verification result is based on occurrence of an event. In embodiments, the event includes at least one of receiving a predetermined output signal or after a predetermined period of time has elapsed.
[0038] To further explain, Figure 8A flowchart of another example method 800 for automatic verification of hardware cryptographic implementations according to embodiments of the present disclosure is set forth. The method 800 is substantially the same as the method 700, except that the applying 710 of the stimuli to the hardware implementation further includes mapping 802 signals of the hardware implementation to corresponding equivalent elements of the reference implementation. Figure 7 In particular embodiments, the equivalent elements include at least one of variables or functions of the reference implementation. In particular embodiments, mapping the signals of the hardware implementation to corresponding equivalent elements of the reference implementation further includes receiving user input specifying the mapping of the signals of the hardware implementation to the corresponding equivalent elements of the reference implementation.
[0039] In view of the explanations set forth above, the reader will recognize that the benefits of performing automatic verification of hardware cryptographic implementations according to embodiments of the present disclosure include:
[0040] • reducing development and verification time of implementing cryptographic hardware components.
[0041] • providing a compiled library of cryptographic reference models to allow reuse during subsequent verification processes.
[0042] • reducing cryptographic algorithm knowledge required by verification engineers to verify cryptographic designs.
[0043] The exemplary embodiments of the present disclosure are primarily described in the context of a fully functional computer system for performing automatic verification of hardware cryptographic implementations. However, those skilled in the art will recognize that the present disclosure can also be embodied in a computer program product disposed on a computer readable storage medium for use with any suitable data processing system. Such computer readable storage medium can be any storage medium for machine-readable information, including magnetic media, optical media, or other suitable medium. Examples of such media include magnetic disks in hard drives or diskettes, compact disks for optical drives, magnetic tape, and others as will occur to those skilled in the art. Those skilled in the art will immediately appreciate that any computer system having suitable programming means will be capable of executing the steps of the method of the present disclosure embodied in a computer program product. Those skilled in the art will further recognize that, although some of the exemplary embodiments described in this specification are oriented to software installed and executed on computer hardware, alternative embodiments implemented as firmware or as hardware are well within the scope of the present disclosure.
[0044] The present application can be a system, a method, and / or a computer program product. The computer program product can include a computer readable storage medium (or media) having computer readable program instructions thereon for causing a processor to carry out aspects of the present application.
[0045] The computer readable storage medium can be a tangible device that can retain and store instructions for use by an instruction execution device. The computer readable storage medium can be, for example, but is not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. A non-exhaustive list of more specific examples of the computer readable storage medium includes the following: a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), a static random access memory (SRAM), a portable compact disc read-only memory (CD-ROM), a digital versatile disk (DVD), a memory stick, a floppy disk, a mechanically encoded device such as punch-cards or raised structures in a groove having instructions recorded thereon, and any suitable combination of the foregoing. A computer readable storage medium, as used herein, is not to be construed as being transitory signals per se, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through a waveguide or other transmission media (e.g., light pulses passing through a fiber-optic cable), or electrical signals transmitted through a wire.
[0046] Computer readable program instructions described herein can be downloaded to respective computing / processing devices from a computer readable storage medium or to an external computer or external storage device via a network, for example, the Internet, a local area network, a wide area network and / or a wireless network. The network can comprise copper transmission cables, optical transmission fibers, wireless transmission, routers, firewalls, switches, gateway computers and / or edge servers. A network adapter card or network interface in each computing / processing device receives computer readable program instructions from the network and forwards the computer readable program instructions for storage in a computer readable storage medium within the respective computing / processing device.
[0047] Computer readable program instructions for carrying out operations of the present application can be assembly instructions, instruction-set-architecture (ISA) instructions, machine instructions, machine dependent instructions, microcode, firmware instructions, state-setting data, or source code or object code written in any combination of one or more programming languages, including an object oriented programming language such as Smalltalk, C++ or the like, and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The computer readable program instructions can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider). In some embodiments, electronic circuitry including, for example, programmable logic circuitry, field-programmable gate array (FPGA), or programmable logic array (PLA) can execute the computer readable program instructions by utilizing state information of the computer readable program instructions to personalize the electronic circuitry, in order to perform the functions described herein.
[0048] The computer readable program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus or other device to produce a computer implemented process such that the instructions which execute on the computer, other programmable apparatus, or other device implement the functions / acts specified in the flowchart and / or block diagram block or blocks.
[0049] These computer readable program instructions can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks. These computer readable program instructions can also be stored in a computer readable storage medium that can direct a computer, a programmable data processing apparatus, and / or other devices to function in a particular manner, such that the computer readable storage medium having instructions stored therein comprises an article of manufacture including
[0050] The computer readable program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus or other device to produce a computer implemented process such that the instructions which execute on the computer, other programmable apparatus, or other device implement the functions / acts specified in the flowchart and / or block diagram block or blocks.
[0051] The flow and block diagrams in the drawings show the architectural, functional, and operational aspects of possible implementations of systems, methods, and computer program products according to various embodiments of the present application. In that regard, each block in the flow or block diagrams can represent a module, segment, or portion of instructions, which includes one or more executable instructions for implementing the specified logical function(s). In some alternative implementations, the functions noted in the blocks can occur out of the order noted in the figures. For example, two blocks shown in succession can in fact be executed substantially concurrently or the blocks can sometimes be executed in the reverse order, depending upon the functionality involved. Such variations will depend on the functionality of the particular application and how the underlying technology functions. Also, each block in the block diagrams and / or flow diagrams illustrations, and combinations of blocks in such illustrations, can be implemented by special purpose hardware-based systems that perform the specified functions or actions, or combinations of special purpose hardware and computer instructions.
[0052] From the foregoing description, it will be apparent that modifications and variations can be effected while remaining within the scope of the application as defined by the appended claims. The description is intended to be illustrative, and not to be limiting. The scope of the disclosure is limited only by the language of the following claims.
Claims
1. A method for automatic verification of hardware cryptographic implementations, the method comprising: receiving a reference implementation of a cryptographic algorithm; receiving test case data associated with the cryptographic algorithm; generating stimuli based on the test case data; applying the stimuli to the reference implementation using a simulation model to generate first intermediate state results; applying the stimuli to a hardware implementation of the cryptographic algorithm using the simulation model to generate second intermediate state results; and generating a verification result based on a comparison of the first intermediate state results and the second intermediate state results.
2. The method of claim 1, wherein applying the stimuli to the hardware implementation further comprises mapping signals of the hardware implementation to corresponding equivalent elements of the reference implementation.
3. The method of claim 2, wherein the equivalent elements comprise at least one of variables or functions of the reference implementation.
4. The method of claim 2 or 3, wherein mapping signals of the hardware implementation to corresponding equivalent elements of the reference implementation further comprises receiving user input specifying the mapping of signals of the hardware implementation to corresponding equivalent elements of the reference implementation.
5. The method of any preceding claim, further comprising determining expected output signals of the hardware implementation based on the test case data and the reference implementation.
6. The method of any preceding claim, wherein generating the verification result is based on an occurrence of an event.
7. The method of claim 6, wherein the event comprises at least one of receiving a predetermined output signal or after a predetermined period of time has elapsed.
8. An apparatus for automatic verification of hardware cryptographic implementations, the apparatus comprising: a computer processor; and a computer memory operably coupled to the computer processor, the computer memory having computer program instructions disposed within it which, when executed by the computer processor, cause the apparatus to: receive a reference implementation of a cryptographic algorithm; receive test case data associated with the cryptographic algorithm; generate stimuli based on the test case data; apply the stimuli to the reference implementation using a simulation model to generate first intermediate state results; apply the stimuli to a hardware implementation of the cryptographic algorithm using the simulation model to generate second intermediate state results; and generate a verification result based on a comparison of the first intermediate state results and the second intermediate state results.
9. The apparatus of claim 8, wherein applying the stimuli to the hardware implementation further comprises mapping signals of the hardware implementation to corresponding equivalent elements of the reference implementation.
10. The apparatus of claim 9, wherein the equivalent elements comprise at least one of variables or functions of the reference implementation.
11. The apparatus of claim 9 or claim 10, wherein mapping signals of the hardware implementation to corresponding equivalent elements of the reference implementation further comprises receiving user input specifying the mapping of signals of the hardware implementation to corresponding equivalent elements of the reference implementation.
12. The apparatus of any of claims 8 to 11, wherein the computer program instructions further cause the apparatus to determine an expected output signal of the hardware implementation based on the test case data and the reference implementation.
13. The apparatus of any of claims 8 to 12, wherein generating the verification result is based on an occurrence of an event.
14. The apparatus of claim 13, wherein the event comprises at least one of receiving a predetermined output signal or after a predetermined period of time elapses.
15. A computer program product, the computer program product being set on a computer readable medium, the computer program product comprising computer program instructions that, when executed, cause a computer to: receive a reference implementation of a cryptographic algorithm; receive test case data associated with the cryptographic algorithm; generate stimuli based on the test case data; apply the stimuli to the reference implementation using a simulation model to generate a first intermediate state result; apply the stimuli to a hardware implementation of the cryptographic algorithm using the simulation model to generate a second intermediate state result; and generate a verification result based on a comparison of the first intermediate state result and the second intermediate state result.
16. The computer program product of claim 15, wherein applying the stimuli to the hardware implementation further comprises mapping signals of the hardware implementation to corresponding equivalent elements of the reference implementation.
17. The computer program product of claim 16, wherein the equivalent elements comprise at least one of a variable or a function of the reference implementation.
18. The computer program product of claim 16 or 17, wherein mapping signals of the hardware implementation to corresponding equivalent elements of the reference implementation further comprises receiving user input specifying a mapping of signals of the hardware implementation to corresponding equivalent elements of the reference implementation. the computer program instructions further cause the computer to determine an expected output signal of the hardware implementation based on the test case data and the reference implementation.
20. The computer program product of any of claims 15 to 19, wherein generating the verification result is based on an occurrence of an event. 19. The computer program product of any one of claims 15 to 18, wherein,