Verification system and verification method

The verification system uses a quantum computer to convert design information into a satisfiability problem, then into a maximum independent set problem, addressing the inefficiencies of conventional methods by reducing computational intensity and skill requirements for large-scale design verification.

JP2025136252AActive Publication Date: 2025-09-19TOSHIBA INFORMATION SYSTEMS (JAPAN) CORPORATION
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2024034592
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-03-07
Publication Date
2025-09-19
Estimated Expiration
2044-03-07

AI Technical Summary

Technical Problem

Conventional methods for verifying large-scale design results, such as logic circuits, are computationally intensive and require specialized skills, making them time-consuming and inefficient.

Method used

A verification system utilizing a quantum computer to convert design information into a satisfiability problem, then into a conjunctive normal form (CNF), and further into a maximum independent set problem using an Ising model, determining the spin direction of quanta to assess the design's satisfiability or unsatisfiability.

Benefits of technology

Reduces verification time and eliminates the need for specialized skills, enabling efficient verification of large-scale designs by leveraging quantum computing for faster and more accurate results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025136252000001_ABST
    Figure 2025136252000001_ABST
Patent Text Reader

Abstract

To minimize a time required for verifying a resultant object of large-scale design.SOLUTION: A verification system for verifying whether or not a resultant object of design has been properly designed, includes: satisfiability problem creating means 31 for creating a satisfiability problem on the basis of design information concerning the resultant object of design; CNF creating means 32 for creating CNF by converting the satisfiability problem to a conjunctive normal form; conversion means 33 for converting the CNF to a maximum independent set problem; Hamiltonian setting means 34 for setting a Hamiltonian of an Ising model from the maximum independent set problem; optimum solution obtaining means 38; and properness / improperness determining means 35 for determining satisfiability / unsatisfiability on the basis of the number of quanta that have a spin direction of "1" as obtained.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a verification system and a verification method for verifying whether a design result has been properly designed. [Background technology]

[0002] In recent years, there has been a problem with the time required for debugging and verifying design results (solution programs), designed programs, and designed logic circuits for optimization problems, including the traveling salesman problem and financial portfolio design. For example, to verify designed logic circuits, formal verification is commonly used as a technique to compensate for the limitations of logic simulation. However, formal verification, by its very nature, is computationally intensive, requiring time to prove properties and making it unsuitable for large-scale circuits. Furthermore, to master formal verification, specialized skills are required to solve the above problems.

[0003] Patent Document 1 discloses that a combinatorial optimization problem is solved using a quantum computer, but does not mention verification of the solution.

[0004] Patent Document 2 describes how the satisfiability problem (hereinafter referred to as SAT) is becoming increasingly used in formal verification, and introduces a method in which, for example, when verifying a gate-level logic circuit, a computer expresses the logic circuit as a logical formula in Conjunctive Normal Form (CNF) and determines whether or not there exists a combination of truth values ​​of variables that makes the entire logical formula true ("1"). Since logical formulas are becoming longer with the increase in circuit scale, Patent Document 2 discloses an improvement to a method in which, for example, a computer (master) divides a logical formula into multiple parts and assigns them to multiple other computers (clients), and processes the divided logical formulas in parallel.

[0005] Patent Document 3 discloses a solution search system that can solve SAT problems quickly and efficiently for different instances using the same circuit without complicating the algorithm when various real-world scheduling problems are formulated as SAT problems, a solution search method using this solution search system, and how this solution search method can be realized by a computer system.

[0006] The invention of Patent Document 3 includes a plurality of data generation units, a fluctuation setting unit that supplies fluctuation probabilities to the data generation units to non-uniformly set the occurrence frequencies of the data generated by the data generation units, and sets the occurrence frequency of a specific variable to a value different from the occurrence frequency of other variables. It also includes a plurality of data conversion units that read the data generated by the data generation units and convert it into information, and an output adjustment unit that transmits an output adjustment signal or an output adjustment signal and a fluctuation probability value to the data generation units. It also includes a feedback control unit that repeatedly controls the operation of transmitting an output adjustment signal or an output adjustment signal and a fluctuation probability value to the data generation units when an optimal solution has not been obtained. [Prior art documents] [Patent documents]

[0007] [Patent Document 1] International Publication No. 2023 / 281742 [Patent Document 2] Japanese Patent Application Laid-Open No. 2013-246657 [Patent Document 3] Japanese Patent Publication No. 2022-075472 Summary of the Invention [Problem to be solved by the invention]

[0008] The embodiments of the present invention provide a verification system and a verification method that do not require as much time as conventional methods when verifying a large-scale design result, and do not require special skills to use the embodiments. [Means for solving the problem]

[0009] A verification system according to an embodiment of the present invention is a verification system for verifying whether a design result is properly designed, and is characterized by comprising: a satisfiability problem creation means for creating a satisfiability problem based on design information of the design result; a CNF creation means for converting the satisfiability problem created by the satisfiability problem creation means into a conjunctive normal form to create a CNF; a conversion means for converting the CNF created by the CNF creation means into a maximum independent set problem; a Hamiltonian setting means for setting a Hamiltonian of an Ising model from the maximum independent set problem obtained by the conversion means; an optimal solution acquisition means configured using a quantum computer, the optimal solution acquisition means determining the spin direction of a quantum that creates a stable state of the set Hamiltonian; and an appropriateness / inappropriateness determination means for determining whether the design result is satisfiable or unsatisfiable based on the number of nodes of the CNF and the number of quanta having a spin direction of "1" determined by the optimal solution acquisition means.

[0010] A verification method according to an embodiment of the present invention is a verification method for verifying whether a design result is properly designed, and is characterized by comprising: a satisfiability problem creation step of creating a satisfiability problem based on design information of the design result; a CNF creation step of creating a CNF by converting the satisfiability problem created in the satisfiability problem creation step into a conjunctive normal form; a conversion step of converting the CNF created in the CNF creation step into a maximum independent set problem; a Hamiltonian setting step of setting a Hamiltonian of an Ising model from the maximum independent set problem obtained in the conversion step; an optimal solution acquisition step executed using a quantum computer, the optimal solution acquisition step determining the spin directions of quanta that create a stable state of the set Hamiltonian; and an appropriateness / inappropriateness determination step of determining whether the design result is satisfiable or unsatisfiable based on the number of nodes of the CNF and the number of quanta having a spin direction of “1” determined in the optimal solution acquisition step. [Brief explanation of the drawings]

[0011] [Figure 1] FIG. 1 is a block diagram of a verification system according to an embodiment of the present invention. [Figure 2] FIG. 2 is a block diagram of functional means realized by an arithmetic control unit 12 of the verification system according to the embodiment of the present invention and functional means realized by a quantum computer 20. [Figure 3] 1 is a flowchart showing the operation of a verification system according to an embodiment of the present invention. [Figure 4] A diagram showing AND circuits, OR circuits, NAND circuits, inverters, and their CNF expressions. [Figure 5] This figure shows the results of substituting 1 and 0 for a, b, and c for the AND circuit to obtain the value of the CNF formula. [Figure 6] A flowchart showing how to synthesize a CNF formula representing the logical structure of a designed logic circuit with a CNF formula representing a logical structure that does not satisfy the design specifications of the logic circuit, and then create a CNF formula that can be converted into a maximum independent set problem. [Figure 7] A diagram showing an example of a CNF formula. [Figure 8] Figure 8 shows a CNF graph created from the CNF formula in Figure 7 . [Figure 9] The CNF graph of Figure 8 is used to show the solution to the maximum independent set problem (MIS). [Figure 10] An explanatory diagram showing that finding the input (combination of quantum spin directions) that minimizes (stable) the value of the Hamiltonian (energy function) is the optimal solution. [Figure 11] This diagram shows a block diagram of a 1-bit multiplexer, the Verilog logic description of this circuit, the CNF we created, and SVA1 and SVA2, which are CNFs that logically invert the content (specifications) we want to check as the behavior of the logic circuit (representing a state where the specifications are not met). [Figure 12] A figure showing a CNF graph created from the CNF in Figure 11 using the above-mentioned rules 1 and 2. [Figure 13] CNF graphs of SVA1 and SVA2 in Figure 11. [Figure 14] This is a diagram of the RTL and SVA1 in Figure 11, where the inverted literals are connected by edges to form a single CNF graph, and a diagram of the CNF graph created by RTL and SVA1 (where a violation exists). [Figure 15] CNF graphs created with RTL and SVA2 (no violations). [Figure 16] FIG. [Figure 17] A diagram showing unsatisfiability as determined by the resolution principle. [Figure 18] 1 is a flowchart of a process including quantum computation and the processing operations of the derivation principle. DETAILED DESCRIPTION OF THE INVENTION

[0012] Hereinafter, an embodiment of the present invention will be described with reference to the accompanying drawings. In each drawing, the same components are assigned the same reference numerals, and duplicate explanations will be omitted. FIG. 1 shows a block diagram of a verification system according to an embodiment of the present invention. The verification system has a classical ordinary computer 10 and a quantum computer 20, and the computer 10 and the quantum computer 20 are connected by communication interfaces 11 and 21. The computer 10 is equipped with an arithmetic control unit 12 consisting of a CPU and a memory unit, an input unit 13 for inputting data, commands, etc. to the arithmetic control unit 12, and a display unit 14 for outputting data and images.

[0013] 2 shows functional means realized by the operation control unit 12 of the computer 10 and functional means realized by the quantum computer 20. That is, the operation control unit 12 includes a satisfiability problem generation means 31, a CNF generation means 32, a conversion means 33, a Hamiltonian setting means 34, a correct / incorrect judgment means 35, a repeat execution process control means 36, and a confirmation means 37, and the quantum computer 20 includes an optimal solution acquisition means 38.

[0014] The satisfiability problem creation means 31 creates a satisfiability problem (SAT) based on the design information of the design result. While the term "design result" is often associated with the discussion of logical verification, the present invention is not limited to this and includes terms such as "conditions" and "constraints" in finance and logistics. Therefore, the satisfiability problem creation means 31 reduces the problem to be solved to a SAT. The CNF creation means 32 converts the satisfiability problem created by the satisfiability problem creation means 31 into a conjunctive normal form (CNF) to create a CNF. The conversion means 33 converts the CNF created by the CNF creation means 32 into a maximum independent set problem (MIS), which, as described below, creates a CNF graph from the CNF formula. The Hamiltonian setting means 34 sets the Hamiltonian of the Ising model from the maximum independent set problem (MIS) obtained by the conversion means 33. The appropriateness / inappropriateness determination means 35 determines whether the design result is satisfiable or unsatisfiable based on the number of nodes of the CNF and the number of quanta having a spin direction of “1” obtained by the optimal solution acquisition means 38.

[0015] The repeat execution process control means 36 repeatedly executes and processes the following as necessary based on the first judgment result of the correct / incorrect judgment means 35: recreating the CNF by the CNF creation means 32; resetting the Hamiltonian by the Hamiltonian setting means 34 using the regenerated CNF; obtaining an optimal solution using the reset Hamiltonian by the optimal solution acquisition means 38; and making a judgment by the correct / incorrect judgment means 35 based on the obtained optimal solution using the reset Hamiltonian. When the correct / incorrect judgment means 35 judges a desired CNF formula as unsatisfiable, the confirmation means 37 repeats operations based on the derivation principle assuming that the desired CNF formula is satisfied, obtains a new CNF formula, and detects logical contradictions in the new CNF formula to confirm the unsatisfiability of the desired CNF formula. The optimal solution acquisition means 38 of the quantum computer 20 is configured using the quantum computer 20 and determines the quantum spin direction that creates a stable state of the set Hamiltonian.

[0016] The design results in this embodiment include solutions to optimization problems including the traveling salesman problem and the design of financial portfolios, designed programs, and designed logic circuits. In the following, we will use an example of verifying that the design results are logic circuits and that they satisfy the specifications.

[0017] The problem of determining whether a logic circuit satisfies a specification is classified as an NP problem. Since it is an NP problem, formal verification reduces it to a satisfiability problem (SAT), which is NP-complete, and solves it. Converting all possible states of a logic circuit into a conjunctive normal form (CNF) with satisfaction conditions and determining whether the state satisfies the specification simultaneously allows comprehensive verification of the validity of the specification. Therefore, in this embodiment, as shown in the processing flowchart of FIG. 3 , a satisfiability problem is created based on the design information (logical structure of the DUT) of the logic circuit, which is the design result (S11). Whether the design result is a traveling salesman problem, a solution to an optimization problem including financial portfolio design, a designed program, or even a "theorem proving assistant" (a tool for debugging software or checking the correctness of theorem proving), the design information (logical structure of the design result) can be used to verify it using this flowchart.

[0018] Here, we will explain CNF (Conjunctive Normal Form). Conjunctive normal form is a type of standardization (normalization) of logical expressions in Boolean logic in mathematical logic, and expresses a logical expression in the form of a conjunction of disjunctive clauses. Conjunctive normal form is written in the form of a conjunction containing one or more disjunctions of one or more literals, such as the following expression:

number

[0019] Literals (variables) connected by logical OR are called clauses, and CNF is a format in which clauses are connected by logical ANDs. In CNF, where clauses contain up to two literals, the satisfiability problem can be solved in polynomial time, but it is known that when clauses contain three or more literals, the satisfiability problem becomes NP-complete.

[0020] When a logic circuit is converted into CNF, it is as shown in Figure 4. Here, an AND circuit, an OR circuit, a NAND circuit, and an inverter are shown.

[0021] If we substitute 1 and 0 into a, b, and c for the AND circuit and obtain the value of the CNF formula, we get the result shown in Figure 5. If we check the combinations of variable values ​​that result in a 1 (satisfied), we find that the relationship is c=(a & b). In other words, the satisfied conditions of the CNF formula converted from the logic circuit are the combinations of all the states that the logic circuit can have.

[0022] The CNF created from RTL is always satisfied, and the satisfying condition is any state of the circuit. The SAT solver searches whether it can be satisfied at the same time as the CNF that represents a state that does not satisfy the specification created from SVA (System Verilog Assertion). If a satisfying condition exists in this state, it means that there is a state that the circuit can take that does not satisfy the specification, which means that a defect (bug) exists.

[0023] As we have already explained, the computational resources required for this SAT solver would be enormous on a classical computer (an NP-complete problem).The goal is to reduce the computation flow for conventional formal verification to an Ising model using the processing flow shown in the flowchart above in Figure 3, so that it can ultimately be used for quantum computation.

[0024] In the next step, the created satisfiability problem is converted into a conjunctive normal form (CNF) (S12). In this embodiment, as shown in FIG. 6(A), a CNF for the DUT and a CNF for the "negation (NOT)" of the requirements specification are created using SVA, which is used to "reduce visual inspection omissions" and "early bug detection." These are then combined with an "AND" (FIG. 6(B)) to create the final CNF. In other words, since the design result in this embodiment is a designed logic circuit, in the CNF creation step S12, a CNF formula representing the logical structure of the designed logic circuit and a CNF formula representing a logical structure that does not satisfy the design specifications of the logic circuit are combined and then converted into a maximum independent set problem (MIS). The conjunctive normal form (CNF) converted from the logic circuit can be mechanically converted to 3-CNF using Tseitin encoding. In the satisfiability problem (SAT), it is known that 2-SAT is P and NP-complete if 3-SAT or higher is NP-complete. Therefore, SAT solvers are based on 3-SAT.

[0025] Next, the CNF created above is converted into a maximum independent set problem (MIS) (S13). Here, the satisfiability problem is reduced to an Ising model in order to solve it using quantum computing. That is, to reduce it to the Ising model, the satisfiability problem is first converted into a maximum independent set problem (MIS).

[0026] In this conversion step S13, for 3-CNFs with up to three literals in a clause, a graph in which the three literals in the clause are triangles as vertices, and a graph in which the literals are connected by edges only when there are two literals, are created based on the following rules 1 and 2, and this graph is converted into an Ising model. In other words, the graph is regarded as an Ising model of MIS and formulated. Rule 1: If multiple clauses share the same literal, they do not overlap as vertices in the graph. Rule 2: Positive and negative literals are also connected by edges.

[0027] According to the above rules, graphs can be created from the CNF formula shown in Figure 7, as shown in Figures 8(A) and 8(B). The vertices (literals) of the graph are quanta, and the value of the literal is the spin direction of the quantum. The edges of the graph are expressed as dependencies between quanta. When a positive literal and a negative literal are connected, the edge is shown by a dashed line.

[0028] The Hamiltonian of the Ising model is set from the maximum independent set problem obtained as described above (S14). In this maximum independent set problem (MIS), "when formulating, a constraint is added that adjacent vertices must not be "1"," so that the ground state of energy represents the optimal solution of the MIS. Also, the more "1"s each vertex has, the smaller and more stable the overall amount of energy becomes. Taking these factors into consideration, the Hamiltonian (energy function) is set.

[0029] The stable state of the Hamiltonian (energy function) in this Ising model represents the solution to the maximum independent set problem (MIS) of the graph. Adjacent quanta of the same value on a dashed edge are not connected, and "1"s do not share an edge, while the state containing the most "1"s is stable. The number of "1"s at this point is the maximum number of independent sets, and it is known that if the maximum value of the independent set is equivalent to the number of nodes in the 3-CNF, this 3-CNF is satisfiable. Taking these factors into consideration, the stable state of the Hamiltonian (energy function) is achieved when the vertices indicated by the white inverted characters in Figure 9 are set to "1."

[0030] The Hamiltonian (energy function) of the Ising model is expressed by the following equation.

number

[0031] As shown in Fig. 10, in quantum computing, the optimal solution is found by finding the input (combination of quantum spin directions) that minimizes (stables) the value of the Hamiltonian (energy function). This process is shown in step S15 in the flowchart of Fig. 3.

[0032] If this 3-CNF is a composite (Assert Property) of the logic circuit and the inverted state of the required specifications, as shown in Figure 6(B), then satisfiability indicates that there is a common satisfaction condition between the logic circuit and the state that does not satisfy the required specifications, i.e., there is a bug (specification violation). On the other hand, if the maximum value of the independent set is not the number of nodes in the 3-CNF, it becomes unsatisfiable, and the logic circuit always satisfies the specifications. This process is shown in step S16 in the flowchart in Figure 3.

[0033] Furthermore, if the condition is satisfiable (maximum number of independent sets = number of CNF clauses), a counterexample (bug waveform) can be shown using conventional formal verification methods by feeding back to the SAT solver the conditions under which the independent sets were extracted from the graph. If the condition is unsatisfiable, the CNF formula is checked for empty clauses using the resolution principle. Furthermore, if an empty clause is generated when a new clause is derived from the literals connected by dashed lines on the graph and the operation is repeated, the CNF is found to be unsatisfiable.

[0034] Determining the quantum spin direction that creates a stable state of the Hamiltonian (energy function) of the Ising model is an area of ​​expertise for the quantum annealing machine, which is the quantum computer 20 used in this embodiment, and even if the number of literals is in the millions or tens of millions, a solution can be found in a shorter time than deterministic calculation of an NP problem of the same input size. By comparing the spin direction with the number of nodes of the CNF converted from the logic circuit, it can be determined whether the logic circuit satisfies the specifications.

[0035] In this embodiment, the logic circuit to be verified and the specifications (logical structure) required for that logic circuit are each converted into a 3-CNF formula. A graph is created to reduce the 3-CNF to the maximum independent set problem, and quantum calculation is performed as an Ising model. The results of this quantum calculation cannot be guaranteed to be the optimal solution as is. Therefore, the calculation results (decision results) and the information on the spin direction assigned to the quantum, which is its condition, are fed back to the SAT solver as a 3-CNF formula and the values ​​of each literal.

[0036] In a SAT solver, it is possible to use the results of quantum computation as a witness and verify the validity of the judgment result in polynomial time (realistic time). When the SAT solver finds that the quantum computation judgment is incorrect, the accuracy of the solution can be improved by updating the conditions of the CNF graph as a stricter quantum interrelationship for the inconsistent literals and re-running the quantum computation.

[0037] In the verification of this embodiment, when the result of quantum computation is judged to be "unsatisfiable," it is important to confirm its validity. However, if we confirm that the inversion literals (meaning a pair of a positive literal and a negative literal) in the graph are correctly placed, and then repeat the operation of deriving a new node from the inversion literal, and confirm that an empty node (a node that does not contain any literals) is generated, then we can confirm that the result is unsatisfiable.

[0038] Although the examples explained above using Figures 7 to 10 did not show specific examples of logic circuits to be verified, we will explain using a 1-bit multiplexer. Figure 11 shows a block diagram of this 1-bit multiplexer, the Verilog logic description of this circuit, the created CNF, and SVA1 and SVA2, which are CNFs that logically invert the content (specifications) to be confirmed as the behavior of the logic circuit (representing a state where the specifications are not met).

[0039] If we create a graph from the above CNF using the rules 1 and 2, it will look like the one shown in Figure 12. SVA1 and SVA2 are also converted into graphs, as shown in Figures 13(A) and 13(B).

[0040] If inversion literals in RTL and SVA1 are connected with edges to form a single CNF graph, the result will be as shown in Figure 14. In other words, Figure 14 shows an attempt to derive the SAT (maximum independent set problem) of whether RTL and SVA1 can be simultaneously satisfied by solving MIS using a CNF graph. The black nodes represent MIS, and since their number is equivalent to the number of CNF clauses, they directly indicate the CNF satisfaction conditions (violations within the circuit). Furthermore, when inversion literals are connected with edges in RTL and SVA2 to form a single CNF graph, it becomes as shown in Figure 15. When vertices set to "1" (white inverted characters) are prevented from connecting with each other with edges, the maximum number of vertices set to "1" that can be placed is determined, which is the maximum independent set problem (MIS). In Figure 15, the number of CNF nodes and the number of MIS are different, which indicates unsatisfiability (there is no violation within the circuit).

[0041] The graph in Figure 14 is a graph made with RTL and SVA1 (where a violation exists), and seven vertices can be placed. This is equivalent to a CNF made with RTL and SVA1 that has seven nodes, and it is known that in such cases the CNF is satisfiable. The vertices (variables) that are actually set to "1" directly indicate a malfunction (violation state) in the logic circuit. In this case, the circuit state where S=0, A=0, B=1, C=0 (when S=0, A=C in operation) indicates a violation of the contents of SVA1.

[0042] The graph in Figure 15 is a graph created using RTL and SVA2 (no violations exist), and only six vertices can be placed. In this case, the number of MIS nodes differs from the number of CNF clauses, and the CNF is determined to be unsatisfiable. The Hamiltonian representing this maximum independent set problem using the Ising model is given by the following equation.

number

[0043] SiSj is the logical product, and when Si and Sj are both 1, a penalty is set with coefficient J. On the other hand, h gives a bonus when Si is 1. In other words, the state of each vertex that minimizes the value of the entire equation is maximized when no "1"s are placed next to each other. A quantum computer, which is a quantum annealer, can find a solution to this calculation in an extremely short time. If a satisfied result is obtained for the graph in Figure 14, it is possible to confirm whether the obtained solution is correct by feeding back the final vertex state to the logic circuit as described above. In contrast, if an unsatisfiable result is obtained for the graph in Figure 15, it is determined that "the condition is not satisfied," so it is not possible to confirm whether the solution is actually satisfied or not.

[0044] For the above confirmation, in this embodiment, when the correctness / incorrectness determination means 35 determines that the required CNF formula is unsatisfiable, the confirmation means 37 assumes that the required CNF formula is satisfiable, repeats the operation based on the derivation principle to obtain a new CNF formula, and detects logical contradictions in the new CNF formula, thereby confirming that the required CNF formula is unsatisfiable.

[0045] First, the derivation principle will be explained. If a CNF formula is satisfiable, then each clause in the satisfiability condition must be 1. If (A|B|C)&(D|E|F)=1, then (A|B|C)=1 and (D|E|F)=1. On the other hand, it is always true that ((A → B) & (B → C)) → (A → C). (Deductive syllogism) If ((A→B)&(B→C))=1, then (A→C)=1 is always true. In other words, if ((!A|B)&(!B|C))=1, then (!A|C)=1 always holds.

[0046] As shown in Figure 16, ((!A|B)&(!B|C)) has the form 2CNF, where B is an inversion literal across clauses. In Figure 14, it is declared that if this CNF formula is =1 (i.e., satisfied), then (!A|C)=1, which shows that if the inverted literals B and !B are deleted and the remaining literals are connected with a logical OR, it can also be satisfied as a new clause.

[0047] Using the above inverse literal elimination technique, if a logical contradiction arises in the process of assuming that a CNF formula is satisfied and repeating operations based on the resolution principle, it is possible to prove by contradiction that the CNF formula is unsatisfiable (this is called a refutation proof).

[0048] Returning to the CNF graph shown in Figure 12, created from RTL and SVA2, we see that the following holds:

number

[0049] (1) Since there is a simple literal "S", if we want to satisfy CNF, then S = 1. The entire clause containing S and the literal !S can be deleted from the clause. This results in the following expression:

number

[0050] (2) When the resolution principle is applied to C, which has the most connections among the inverted literals {B, C} connected at C6, which could not be made into an independent set, the result is as follows. (!B|C),(B|!C) [Derive a new clause from (1) and (2)] →(B|!B)=1 (!B|C),(!B|!C) [Derive a new clause from (1) and (3)] →(!B|!B) =!B (B|C),(B|!C) [Derive a new clause from (4) and (2)] →(B|B)=B (B|C),(!B|!C) [Derive a new clause from (4) and (3)] →(B|!B)=1

[0051] Delete the original clause above and create a CNF with new clause [(B|!B)=1], new clause [(!B|!B) =!B], new clause [(B|B)=B] and new clause [(B|!B)=1] (connect them with AND). As a result, 1&!B&B&1=1, which is !B&B=1. As a result, the result of satisfiability / unsatisfiability is "unsatisfiable" because a contradictory formula is obtained as shown in Figure 17.

[0052] Since the graph created from an actual logic circuit is huge, it is necessary to find where the inversion literals across nodes exist in order to prove the refutation. This information is known when creating a CNF graph. In addition, as a result of solving the MIS, the nodes where a vertex of "1" cannot be set are known, and the inversion literals that these nodes share with other nodes are also known. By using this information in the refutation proof, it is possible to perform efficient resolution principle processing operations and confirm unsatisfiability. A flowchart of this process is shown in Figure 18.

[0053] The optimal solution is obtained using quantum computation, and a judgment of whether it is satisfiable or not is made in step S21, which judges whether it is correct or not based on the optimal solution. If it is judged to be satisfiable, the SAT solver confirms it by feedbacking the spin state (step S22). If it is judged to be satisfiable, the processing operation of the derivation principle described above is performed (step S23). The result of whether there is a contradiction or not is obtained in step S23. If the obtained result is contradictory, it is judged to be unsatisfiable, and if the output is consistent, an inversion literal is detected by creating a CNF graph (step S24). If the detection of an inversion literal results in "yes," the process returns to step S23. If the detection of an inversion literal results in "no," a judgment of satisfiability is made. The above processing is performed.

[0054] Even when the CNF is unsatisfiable, the MIS calculation still seems to be searching for the maximum number of independent sets that can be set. Although it is not clear whether the difficulty of the problem on the quantum annealer is different when the number of maximum independent sets can be set to the same number as the number of nodes or when it is one less, both are still optimal solutions. If the difficulty does not change, it is likely that the unsatisfiable condition is determined with the same accuracy as when a bug is generated. On the other hand, if the difficulty changes (increases), it may be incorrectly determined to be unsatisfiable, and there is a problem in that it is difficult to distinguish this from the outside.

[0055] In this embodiment, a method using the resolution principle is presented as a method for directly checking unsatisfiability, but it is important to consider whether the resolution principle can improve the efficiency of processing operations. When an unsatisfiability judgment is made, reliability can be demonstrated if the same result is obtained by recalculating several times by changing the initial state or conditions (parameters), so such a method can also be considered.

[0056] For the above recalculation, this embodiment is provided with a repeated execution process control means 36 which, based on the first judgment result by the appropriateness / inappropriateness judgment means 35, repeatedly controls the execution process as necessary of the following: recreating a CNF by the CNF creation means 32; reconverting to a maximum independent set problem by the conversion means 33 using the recreated CNF; resetting a Hamiltonian by the Hamiltonian setting means 34 using the reconverted maximum independent set problem; obtaining an optimal solution using the reset Hamiltonian by the optimal solution acquisition means 38; and judgment by the appropriateness / inappropriateness judgment means 35 based on the obtained optimal solution using the reset Hamiltonian.

[0057] As described above, this embodiment uses the above-mentioned suitability / inappropriateness judgment based on obtaining an optimal solution using a Hamiltonian to solve problems related to processing time and skill, such as the number of branches in a program or the circuit size in a logic circuit, thereby improving the performance of the verification system. When applied to the LSI field, this will lead to a reduction in the number of man-hours required for product development, thereby improving competitiveness. [Explanation of symbols]

[0058] 10. Computers 11,21 Communication Interface 12 Calculation control unit 13 Input section 14 Display section 20 Quantum Computer 31 Satisfiability problem generation method 32 CNF creation means 33 Conversion Methods 34 Hamiltonian setting method 35 Appropriateness / inappropriateness determination method 36 Repeated execution processing control means 37 Verification Methods 38 Means of obtaining optimal solution

Claims

1. In a verification system that verifies whether a design result is properly designed, a satisfiability problem generating means for generating a satisfiability problem based on design information of the design result; a CNF generating means for converting the satisfiability problem generated by the satisfiability problem generating means into a conjunctive normal form to generate a CNF; a conversion means for converting the CNF generated by the CNF generation means into a maximum independent set problem; Hamiltonian setting means for setting a Hamiltonian of an Ising model from the maximum independent set problem obtained by the conversion means; an optimal solution acquisition means configured using a quantum computer, which obtains a quantum spin direction that creates a stable state of the set Hamiltonian; a correct / incorrect determination means for determining whether a design result is satisfiable or unsatisfiable based on the number of nodes of the CNF and the number of quanta having a spin direction of "1" obtained by the optimal solution acquisition means; A verification system comprising:

2. 2. The verification system according to claim 1, further comprising a repeat execution process control means for repeatedly executing and controlling the following processes as necessary based on the first judgment result by the appropriateness / inappropriateness judgment means: recreating a CNF by the CNF creation means; reconverting the re-created CNF into a maximum independent set problem by the conversion means using the re-created CNF; resetting a Hamiltonian by the Hamiltonian setting means using the re-converted maximum independent set problem; obtaining an optimal solution using the reset Hamiltonian by the optimal solution acquisition means; and judgment by the appropriateness / inappropriateness judgment means based on the obtained optimal solution using the reset Hamiltonian.

3. 2. The verification system according to claim 1, wherein the means for determining whether a design result is satisfiable or unsatisfiable compares the number of quanta having a spin direction of "1" with the number of nodes of a CNF converted from a logic circuit.

4. The verification system according to claim 1, wherein the conversion means creates, for a 3-CNF with up to three literals in a clause, a graph in which the three literals in the clause are used as vertices, and a graph in which the literals are connected by edges only when there are two literals, based on the following rules 1 and 2, and uses this graph as an Ising model. Rule 1: If multiple clauses share the same literal, they cannot overlap as vertices in the graph. Rule 2: Positive and negative literals are also connected by edges.

5. The verification system according to claim 1, further comprising a confirmation means for, when the validity / invalidity determination means determines that the required CNF formula is unsatisfiable, repeating the operations based on the derivation principle on the assumption that the required CNF formula is satisfied to obtain a new CNF formula, and detecting a logical contradiction in the new CNF formula, thereby confirming that the required CNF formula is unsatisfiable.

6. 2. The verification system according to claim 1, wherein the design results include solutions to optimization problems including the traveling salesman problem and financial portfolio design, designed programs, and designed logic circuits.

7. 2. The verification system according to claim 1, wherein the design result is a designed logic circuit, and the CNF creation means combines a CNF formula representing the logical structure of the designed logic circuit with a CNF formula representing a logical structure that does not satisfy the design specifications of the logic circuit, and creates a CNF formula to be converted by the conversion means.

8. A verification method for verifying whether a design result is properly designed, a satisfiability problem creation step of creating a satisfiability problem based on design information of the design resultant product; a CNF generation step of converting the satisfiability problem generated in the satisfiability problem generation step into a conjunctive normal form to generate a CNF; a conversion step of converting the CNF generated by the CNF generation step into a maximum independent set problem; a Hamiltonian setting step of setting a Hamiltonian of an Ising model from the maximum independent set problem obtained by the conversion step; an optimal solution acquisition step executed using a quantum computer, which obtains a quantum spin direction that creates a stable state of the set Hamiltonian; a suitability / unsatisfiability determination step of determining whether a design result is satisfiable or unsatisfiable based on the number of nodes of the CNF and the number of quanta having a spin direction of "1" obtained by the optimal solution acquisition step; A verification method comprising:

9. The verification method according to claim 8, further comprising a repeated execution process control step for repeatedly controlling the execution process as necessary of the following based on the first judgment result of the appropriateness / inappropriateness judgment step: recreating a CNF in the CNF creation step; reconverting to a maximum independent set problem in the conversion step using the re-created CNF; resetting a Hamiltonian in the Hamiltonian setting step using the re-converted maximum independent set problem; obtaining an optimal solution using the Hamiltonian reset in the optimal solution acquisition step; and judgment by the appropriateness / inappropriateness judgment step based on the obtained optimal solution using the reset Hamiltonian.

10. 9. The verification method according to claim 8, wherein the correctness / incorrectness determination step determines whether the design result is satisfiable or unsatisfiable by comparing the number of quanta having a spin direction of "1" with the number of nodes of the CNF converted from the logic circuit.

11. The verification method according to claim 8, wherein in the conversion step, for a 3-CNF with up to three literals in a clause, a graph in which the three literals in the clause are used as vertices is created based on the following rules 1 and 2, and the graph is used as the Ising model. Rule 1: If multiple clauses share the same literal, they cannot overlap as vertices in the graph. Rule 2: Positive and negative literals are also connected by edges.

12. The verification method according to claim 8, further comprising a confirmation step of, when the validity determination step determines that the required CNF formula is unsatisfiable, repeating the operation based on the derivation principle under the assumption that the required CNF formula is satisfied to obtain a new CNF formula, and detecting a logical contradiction in the new CNF formula, thereby confirming that the required CNF formula is unsatisfiable.

13. 9. The verification method according to claim 8, wherein the design results include solutions to optimization problems including the traveling salesman problem and financial portfolio design, designed programs, and designed logic circuits.

14. 9. The verification method according to claim 8, wherein the design result is a designed logic circuit, and the CNF creation step combines a CNF formula representing a logical structure of the designed logic circuit with a CNF formula representing a logical structure that does not satisfy a design specification of the logic circuit to create a CNF formula to be converted in the conversion step.

Citation Information

Patent Citations

  • Analog processor with quantum device

    JP2008525873A

  • Satisfiability problem calculation method, satisfiability problem calculation system and program

    JP2013246657A

  • Verification program, verification method, and verification device

    JP2015172873A

  • Simulated annealing device and simulated annealing method

    WO2022264414A1

  • Solution search system, solution search method, and solution search program

    JP2022075472A