Computer-implemented methods for compressing a digital connectivity representation of an integrated circuit
The method addresses the inefficiencies in reverse engineering complex ICs by using functional connectivity templates to compress and process IC data more efficiently, reducing computational power and time.
Patent Information
- Application Number
- PCT/CA2025/050029
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-01-10
- Filing Date
- 2025-01-09
- Publication Date
- 2025-07-17
AI Technical Summary
The process of reverse engineering integrated circuits (ICs) is costly and time-consuming due to the exponential growth in complexity of digital-domain ICs, leading to resource constraints in processing and storage requirements for large reverse engineered netlists, and existing methods are inefficient for high-complexity ICs.
A computer-implemented method for compressing a digital connectivity representation of ICs by using functional connectivity templates to identify and flag or replace template occurrences, reducing the dataset size through correspondence testing and validation, allowing for efficient processing and compression of netlists.
The method significantly reduces the computational power and time required for processing IC data by recognizing template structures in large datasets, thereby optimizing the reverse engineering process and minimizing resource constraints.
Smart Images

Figure CA2025050029_17072025_PF_FP_ABST
Abstract
Description
COMPUTER-IMPLEMENTED METHODS FOR COMPRESSING A DIGITAL CONNECTIVITY REPRESENTATION OF AN INTEGRATED CIRCUITCROSS-REFERENCE TO RELATED APPLICATION
[0001] The instant application claims the benefit of priority to Canadian Patent Application serial number 3,225,705, filed January 10, 2024, and entitled “COMPUTER-IMPLEMENTED METHODS FOR COMPRESSING A DIGITAL CONNECTIVITY REPRESENTATION OF AN INTEGRATED CIRCUIT”, the contents of which are hereby fully incorporated by reference.FIELD OF THE DISCLOSURE
[0002] The present disclosure relates to reverse engineering and design verification of integrated circuits and particularly to computer-implemented methods for compressing a digital connectivity representation of an integrated circuit, as well as related non-transitory computer readable mediums which comprise instructions to carry out such methods.BACKGROUND
[0003] Integrated circuit (IC) designers utilize electronic design automation software to design and analyze ICs, where various forms of abstraction reduce the circuit complexity from sometimes billions of components to more manageable numbers. In the design of ICs, several design flow characterisations can be made, including a high-level synthesis which is converted to register-transfer level (RTL) representing circuitry via the digital signals between hardware registers and the logical operations performed on those signals, and a logic synthesis which translates the RTL into a discrete netlist. Netlists are typically provided in textual format, comprising at least a list of electronic components and interconnections within a circuit.
[0004] When it comes to reverse engineering ICs, none of the synthesis behind the IC design is available to reverse engineers. Starting from the hardware itself, the reverse engineering of ICs is a costly and time-consuming process, such that every effort is made to reduce costs and processing time. In a conventional IC reverse engineering process, the IC is ion beam etched for delayering, the layers are imaged utilizing ascanning electron microscope (SEM), a transmission electron microscope (TEM), scanning capacitance microscope (SCM), or the like, the images are computationally stitched together, and image-based feature recognition is utilized to extract a netlist of the IC. Reverse engineered netlists typically take the form of physical netlists based on physical connections (as opposed to logical connections), and are typically flat, net- based lists based on all connections to the net (as opposed to being clustered around a particular instantiated component or grouped in another way). To determine the logic synthesis or perform any functional analysis, reverse engineers must process the physical netlist further.
[0005] The complexity of ICs, particularly digital-domain ICs, is constantly increasing, such that reverse engineered netlists are growing exponentially in size. Further processing of these increasingly larger reverse engineered netlists thus constrains resources, such as by requiring increased computational power to support processing of larger netlists and / or requiring increased storage. Indeed, the complexity and expense of reserve engineering ICs continues to rise as ICs increase in complexity. Several methods and systems for netlist abstraction are known in the art. Many of these focus on functional netlist analysis, or otherwise on extracting hierarchy during the design process.
[0006] Template matching, as a general concept, has been used to reduce complexity of netlists. United States (U.S.) Patent No. 5,086,477 issued February 4, 1992, to Yu et al. and entitled “AUTOMATED SYSTEM FOR EXTRACTING DESIGN AND LAYOUT INFORMATION FROM AN INTEGRATED CIRCUIT” utilizes template matching in some embodiments. In the circuit recognition phase of the design verification process, small portions of the intermediate representation of the die are matched to one of many "circuit templates" contained in a reference library. The intermediate representation is a feature-based representation of the image yielded from an identification / transformation process, thus being already reduced in complexity. The reference library includes standard cell structures or other circuits and may be constructed as part of the recognition process. The reference library and intermediate representation have the same information, including sets of precompiled identification features. In addition, the reference circuits stored in the reference library contain a schematic of the circuit and corresponding identification labels or names along with thelocations of the connections to each of those elements. One example is an inverter in which the input and output lines are identified as such and are labeled along with the locations of each of the respective external connections. During circuit recognition, the computer scans the intermediate representation, using a searching boundary, attempting to find a match with one of the reference library circuits using the sets of precompiled identification features. Searching boundaries appear to be operator-defined. Individual circuit cells from the library are compared to the internal representation of the die area selected to find template matches. Thresholding techniques are used to determine when a match exists, since 100% matches are rarely achieved. This template matching would be inefficient for reverse engineering modem ICs of high complexity.
[0007] In 1993, a paper entitled “SubGemini-. Identifying SubCircuits using a Fast Subgraph Isomorphism Algorithm” was presented by Ohlrich et al. at the 30thACM / IEEE Design Automation Conference. The paper describes a technologyindependent algorithm which is based predominantly on an extensive graph partitioning. In Phase I, all possible locations of a subcircuit are identified in a main circuit by applying a partitioning algorithm to both circuits to select a key vertex in the subcircuit and identify all possible vertices in the main circuit that may match. This set of vertices is termed a candidate vector. In Phase II, the algorithm verifies whether there is an actual subcircuit at each location of the candidate vector by examining individual vertexes to find a mapping between vertices in the subcircuit and the main circuit. Matches are initially postulated and unique labels are assigned to each vertex which can later be relabeled and verified, the labeling being a key feature of the algorithm. This algorithm is breadth-first, requires exact matching and does not account for external nets being shorted to other external nets of the same subgraph.
[0008] A syntactic matching tool is utilised amongst others in United States Patent No. 6,536,018 published March 18, 2000, to Chrisholm et al. and entitled “REVERSE ENGINEERING OF INTEGRATED CIRCUITS”. The syntactic matching relies on a library of known subcircuits and attempts to find exact matches for these subcircuits within a larger circuit. The disclosure notes that syntactic matching has limited use in circuits of non-trivial complexity, and that it’s literal matching does not easily compensate for slight changes in a subcircuit which have no effect on function. To account for this, the patented method provides a combined and cooperative approachof syntactic matching, semantic matching, and graph analysis and partitioning. The syntactic matching tool requires a priori knowledge of the circuit, and graph analysis and partitioning is relatively important in achieving the combined and cooperative benefits.
[0009] Polygon-based simplification, as a general concept, has been used to reduce complexity of IC layouts during the design phase. One early United States Patent No. 6,289,116 issued September 11, 2001 to Chamberlain and Lam is entitled “COMPUTER-ASSISTED DESIGN ANALYSIS METHOD FOR EXTRACTING DEVICE AND INTERCONNECT INFORMATION”. This patent inter alia describes a method for recreating an IC layout in the form of manually creating a polygon database, creating a netlist using the polygon database and organizing the netlist into functional blocks of increasing complexity, before generating a schematic diagram using the netlist. This method is inherently limited by the step of manually drawing polygons, which is both computationally and labor-intensive.
[0010] A “SCHEMATIC ORGANIZATION TOOL” is disclosed in U.S. Patent No. 6,738,957 published February 21, 2002, to Gont et al. One embodiment of the patented tool provides a process for generating a high-level schematic from a project schematic of basic components, which comprises scanning the project schematic for all instances of a predetermined cell (which comprises a select group of components and their interconnections); and replacing each instance of the predetermined cell with a cell symbol having inputs and outputs to generate the high-level schematic. Another embodiment includes a step of creating a database from the high-level schematic netlist of the signal between the cells, the signals being identified by labels.
[0011] U.S. Patent Application Publication No. 20070256037 entitled “NET-LIST ORGANIZATION TOOLS” was published to Zavadsky et al. on November 1, 2007. This publication describes a need for pattern-matching techniques that can identify groups of transistors or gates based on their electrical connections, rather than on their physical layouts, and discloses a method of organizing circuitry from a netlist into a hierarchy, utilizing the steps of generating a reference pattern, identifying repetitive instances of the reference pattern in the netlist with inexact graph matching and creating a hierarchy within the netlist based on the identified repetitive instances until the netlist is organized into a hierarchy. The reference pattern is generated by a proximity queryengine and due to the inexactness of the graph matching, matches must be prioritized in terms of quality.
[0012] U.S. Patent No. 7,467,365 published March 20, 2008, to Chang et al. is entitled “SANITY CHECKER FOR INTEGRATED CIRCUITS”. Various methods for layout-based circuit sanity checks are described. In one embodiment, a check based or one or more predefined sub-circuits with at least one predefined checking criteria is described, which entails automatically reading a netlist, identifying one or more subcircuits in the netlist which are isomorphic to at least one predefined subcircuit, performing a predefined calculation on the identified device parameter including a leakage strength calculation and comparing the calculation result against predefined checking criteria. Other embodiments include parsing the netlist into a predetermined data format.
[0013] U.S. Patent No. 7,937,678 published December 17, 2009, to Lippmann and Junghanns discloses a “SYSTEM AND METHOD FOR INTEGRATED CIRCUIT PLANAR NETLIST INTERPRETATION”. One embodiment provides a method for planar netlist interpretation of an IC, comprising converting a planar netlist (of atomic elements and nodes between them) to a graphical description (vertices representing atomic elements and / or nodes, and edges representing the other), identifying combinations of vertices and edges that match library device elements, substituting those device elements for the respective combinations and generating a compressed netlist made up of the device elements and the nodes between them. In some embodiments, the device elements comprise gate-level elements. The compressed netlist is stored in a token-based object orientated language format.
[0014] U.S. PatentNo. 8,788,990 published February 18, 2010, to Meserve discloses “REUSE OF CIRCUIT LABELS IN SUBCIRCUIT RECOGNITION”. One computer- implemented method provides for matching a pattern in a main netlist. The method comprises reading in the main netlist and a pattern, both including a plurality of vertices each being a net or a device, computing labels for each of the vertices in the main netlist and the pattern up to a depth appropriate for the pattern (through iterative relabeling to encode topology surrounding and including each vertex, such that vertices with matching topology are assigned a same label in both the main netlist and pattern), matching a vertex of the pattern with one or more vertices of the main netlist using thelabels and storing the labels including data related to depth for each of the vertices in the main netlist.
[0015] U.S. Patent No. 8,701,058 published December 23, 2010, to Zavadsky and Keyes pertains to “INTEGRATED CIRCUIT ANALYSIS SYSTEMS AND METHODS”. The patented method is used on target netlists where higher than gate level functionality is unknown and comprises characterizing a target netlist and reference netlist(s) (typically using alternative hashing), matching these characterizations, extracting matching information and annotating the target netlist using the extracted matching information by associating the target netlist with the higher than gate level functionality of the reference netlist having matched characteristics. This method is characterized as a structural data mining method and can be combined with partitioning hints and heuristics to locate high level library functional blocks in a gate level netlist.
[0016] Several “PATTERN MATCHING TECHNIQUES IN ANALOG AND MIXED SIGNAL CIRCUITS” are disclosed in U.S. Patent No. 9,830,414 published September 8, 2016, to Saghizadeh. One patented computer-implemented method provides for conversion of a low-level netlist to a higher-level netlist, by converting a low-level netlist received into a connected graph, mapping physical location parameters of electronic circuitry onto the connected graph, identifying one or more landmark structures (including recording the physical location) and searching for a pattern in the connected graph by proceeding outwards from an anchor defined by the physical location of the one or more landmark structures. When a pattern is identified, it is replaced in the low-level netlist with a higher-level abstraction representing the pattern in the higher-level netlist. The landmark structures are identified in order less common before more common. Initial landmarks are identified based on those shown to drive the search to converge more quickly.
[0017] More related to power analysis, U.S. Patent No. 10,002,220 published November 2, 2017, to Joseph and Rao discloses “ON THE FLY NETLIST COMPRESSION IN POWER ANALYSIS”. In one embodiment, the method allows for analyzing circuit power by identifying equivalent elements in a source netlist, forming abstract elements by combining the equivalent elements and forming a reduced netlist by substituting the collective equivalent elements for the abstract elements.Metrics or properties associated with the equivalent elements are also combined and associated such that analysis of the reduced netlist is equivalent to analysis of the source netlist. Notably, equivalence is defined as logical or functional equivalence, in different embodiments, and the reduced netlist is based on identification of such equivalence, as opposed to any template identification.
[0018] U.S. Patent Application Publication No. 20210240894 published August 5, 2021, to Kimura et al. is entitled “RECOVERY OF A HIERARCHICAL FUNCTIONAL REPRESENTATION OF AN INTEGRATED CIRCUIT”. In one embodiment, the method starts with text parsing and pruning operations to pre-process the netlist. The parsing and pruning operations are intended to remove portions of the netlist which would not be recognized as syntactically valid hardware description language, thus involves removing comments, headers or extraneous information (in some embodiments, manually). The pre-processed netlist is next converted to a multityped graph via an abstract syntax tree (ABT), generating lists of node names of various node types as the AST is traversed. The multi-type graph thus includes a set of node types representing electronic components, signal transfer between components, an input terminal, an output terminal and a constant signal source. Graph pruning is used to remove unused or redundant nodes, such as removal of redundant wires or buffers. Node standardization can also be used. The resultant graph is said to capture the netlist in a format more readily converted to RTL.
[0019] This background information is provided to reveal information believed by the applicant to be of possible relevance. No admission is necessarily intended, nor should be construed, that any of the preceding information constitutes prior art or forms part of the general common knowledge in the relevant art.SUMMARY
[0020] The following presents a simplified summary of the general inventive concept(s) described herein to provide a basic understanding of some aspects of the disclosure. This summary is not an extensive overview of the disclosure. It is not intended to restrict key or critical elements of embodiments of the disclosure or to delineate their scope beyond that which is explicitly or implicitly described by the following description and claims.
[0021] A need exists for a computer-implemented method for compressing a digital connectivity representation of an integrated circuit (IC), as well as related non- transitory computer readable mediums which comprise instructions to carry out such methods, that overcome some of the drawbacks of known techniques, or at least, provide a useful alternative thereto. Some aspects of this disclosure provide examples of such.
[0022] In accordance with one aspect, there is provided a computer-implemented method of digitally compressing a digital connectivity representation of at least a portion of an IC to be reverse engineered. The computer-implemented method comprises: providing a functional connectivity template comprising template integrated circuit objects and respectively associated object functional types; receiving the digital connectivity representation of at least a portion of the IC, the digital connectivity representation comprising digital object list data generated from observational data collected from the IC and comprising existing integrated circuit objects and respectively associated object functional types; recording a first correspondence between a first template integrated circuit object of the functional connectivity template and a first existing integrated circuit object of the digital object list data, wherein the first correspondence is recorded provided it does not conflict with any previously recorded correspondence; testing a neighbouring existing integrated circuit object of the digital object list data against a neighbouring template integrated circuit object of the functional connectivity template for a second correspondence therebetween. If the neighbouring existing integrated circuit object corresponds with the neighbouring template integrated circuit object, the method comprises recording a second correspondence provided it does not conflict with any previously recorded correspondence and validating the first correspondence recorded. If the neighbouring existing integrated circuit object does not correspond with the neighbouring template integrated circuit object, the method comprises searching for a different neighbouring existing integrated circuit object of the digital object list data against which to test the neighbouring template integrated circuit object of the functional connectivity template, and, if none exists, removing the first correspondence.
[0023] In one embodiment, the step of testing is repeated for at least one more neighbouring existing integrated circuit object of the digital object list data.
[0024] In one embodiment, upon recordal of correspondences between two or more existing integrated circuit objects against all corresponding template integrated circuit objects in the functional connectivity template, the method comprises registering a template occurrence of the functional connectivity template in the digital object list data.
[0025] In one embodiment, registering the template occurrence comprises any one of: flagging the two or more existing integrated circuit objects in the digital object list data with a digital identifier representative of the functional connectivity template; replacing the two or more existing integrated circuit objects in the digital object list data with a digital representation of the functional connectivity template, or the like.
[0026] In one embodiment, upon registration of the template occurrence of the functional connectivity template, the steps of recording and testing are repeated to identify any further occurrences of the functional connectivity template in the digital object list data.
[0027] In one embodiment, the existing integrated circuit obj ects in the digital obj ect list data registered to correspond with the functional connectivity template are not searched in subsequent steps of recording and testing.
[0028] In one embodiment, any one or both of the first correspondence and the second correspondence comprises at least matching object functional types.
[0029] In one embodiment, if the neighbouring template integrated circuit object is of a permutable object functional type, testing the neighbouring existing integrated circuit object comprises testing the neighbouring existing integrated circuit for permuted correspondence with neighbouring template integrated circuit object.
[0030] In one embodiment, the permutable object functional type is a metal-oxide semiconductor (MOS) channel pin connection which is permutable between a source pin and a drain pin.
[0031] In one embodiment, the method comprises a step of receiving a recursiveobject marker assigned to a given existing integrated circuit object of the digital object list data based on visual inspection of the IC. In one embodiment, if the neighbouringexisting circuit object is assigned the recursive-object marker, and if the neighbouring existing integrated circuit object corresponds with the neighbouring template integrated circuit object, the method comprises a step of assuming correspondence of any downstream objects of the neighbouring existing integrated circuit object. In one embodiment, assuming correspondence of any downstream objects comprises recording a correspondence between the neighbouring existing integrated circuit object and the neighbouring template integrated circuit object, and not testing any objects neighbouring the neighbouring existing integrated circuit object assigned the recursiveobject marker. In one embodiment, the recursive-object marker is assigned to one or more existing integrated circuit objects known to be of high complexity, or at least a part of an integrated circuit component of high complexity, which typically requires recursive testing.
[0032] In one embodiment, the method comprises a step of receiving a dispensable- object marker assigned to a given template integrated circuit object of the functional connectivity template. In one embodiment, if the neighbouring template integrated circuit object is assigned the dispensable-object marker, and if no neighbouring existing integrated circuit object if found to correspond with the neighbouring template integrated circuit object, a previously recorded correspondence is still validated. In one embodiment, the dispensable-object marker is assigned to one or more template integrated circuits objects known to be dispensable without significantly altering functioning of a functional connectivity template or a portion thereof.
[0033] In one embodiment, the method comprises a step of receiving a net-location marker assigned to one or more template integrated circuit objects of the functional connectivity template, the net-location marker is any one of an internal-net marker and an external-net marker. In one embodiment, testing comprises determining if two given template integrated circuit objects each assigned the external -net marker correspond to a single existing integrated circuit object, testing for such correspondence allows shorted nets in the functional connectivity template to be identified.
[0034] In one embodiment, the step of recording a first correspondence comprises assuming the first correspondence, the first correspondence is assumed based on any one of: an existing integrated circuit object having the least number of occurrences inthe digital object list data; an existing integrated circuit object identified as being connected to a predefined component in the digital object list data; or the like.
[0035] In one embodiment, the digital connectivity representation comprises a netlist, and the template integrated circuit objects and the existing integrated circuit objects comprise any one or more of: a pin, a net, or an instantiated component.
[0036] In one embodiment, testing comprises treating any one or both of power and ground as special nets in an initial testing iteration. In one embodiment, treating any one or both of power and ground as special nets comprises recognizing any one or both of power and ground as a signal pin.
[0037] In one embodiment, the method is operable on the netlist in the absence of connectivity characteristics associated with p- and n-types. In another embodiment, the template integrated circuit objects and the existing integrated circuit objects comprise connectivity characteristics associated with one of a p-type transistor or a n-type transistor.
[0038] In one embodiment, the functional connectivity template defines a digital logic cell, and the steps of recording and testing are repeated for a plurality of functional connectivity templates each defining different digital logic cells.
[0039] In one embodiment, the plurality of functional connectivity templates is sorted in order of any one or both of: decreasing complexity and decreasing prevalence, and the computer-implemented method compresses the digital connectivity representation by identifying occurrences of each functional connectivity template in such order.
[0040] In one embodiment, the method comprises a preliminary step of deriving at least a part of the digital connectivity representation from one or more images of the IC to be reverse engineered.
[0041] In accordance with another aspect, there is provided a computer- implemented method of digitally compressing a digital connectivity representation of at least a portion of an integrated circuit (IC). The method comprises: providing a functional connectivity template comprising template integrated circuit objects andrespectively associated object functional types; receiving the digital connectivity representation of at least a portion of the IC, the digital connectivity representation comprising digital object list data comprising existing integrated circuit objects and respectively associated object functional types; searching for correspondences between template integrated circuit objects of the functional connectivity template and existing integrated circuit objects of the digital object list data, wherein correspondences are at least partly based on matched object functional types selected from a net, a pin or an instantiated component; recording correspondences provided each correspondence does not conflict with any previously recorded correspondence; validating each correspondence recorded by testing a neighbouring existing integrated circuit object of the digital object list data against a neighbouring template integrated circuit object of the functional connectivity template for correspondence therebetween; and if the correspondences recorded reflect validated correspondences between all template integrated circuit objects of the functional connectivity template and a selection of existing integrated circuit objects from the digital object list data, marking the selection of existing integrated circuit objects with a template identifier.
[0042] In one embodiment, the steps of searching, recording and validating are repeated to find correspondences in a depth-first manner.
[0043] In one embodiment, if a given neighbouring existing integrated circuit object does not correspond with a given neighbouring template integrated circuit object, the method comprises searching for a different neighbouring existing integrated circuit object against which to test the given neighbouring template integrated circuit object, and, if none exists, removing a previously recorded correspondence.
[0044] In accordance with another aspect, there is provided a non-transitory computer readable medium comprising instructions that when executed by a processor, cause the processor to carry out the computer-implemented method as described with reference to either one of the first and second aspects described above.
[0045] Any of the aspects disclosed herein may share features or components with any of the other aspects disclosed herein. Other aspects, features and / or advantages will become more apparent upon reading of the following non-restrictive description ofspecific embodiments thereof, given by way of example only with reference to the accompanying drawings.BRIEF DESCRIPTION OF THE FIGURES
[0046] Several embodiments of the present disclosure will be provided, by way of examples only, with reference to the appended drawings, wherein:
[0047] Figure 1 is a flow diagram of an exemplary computer-implemented method of digitally compressing a digital connectivity representation of at least a portion of an IC, in accordance with one embodiment of the disclosure;
[0048] Figure 2 is a graphic representation of an exemplary functional connectivity template (“template”) on the lefthand side, and a graphic representation of a portion of an exemplary search space on the righthand side, which is traced or tracked with at least one embodiment of the method disclosed herein in an attempt to find a match with the template;
[0049] Figure 3 is a graphic representation of the exemplary template shown in Figure 2 on the lefthand side, and another portion of the exemplary search space shown on the righthand side, which is traced or tracked with at least one embodiment of the method disclosed herein in an attempt to find a match with the template;
[0050] Figure 4 is a circuit diagram of an exemplary functional connectivity template (“template”) on the lefthand side and a circuit diagram of a portion of an exemplary search space (specifically, netlist) on the righthand side, illustrating that at least one embodiment of the disclosed method includes testing for permuted correspondence such that correspondence between this template and this netlist is obtainable;
[0051] Figure 5 is a circuit diagram of an exemplary functional connectivity template (“template”) on the lefthand side, including an inverter, and a circuit diagram of a portion of an exemplary search space (specifically, netlist) on the righthand side, illustrating that at least one embodiment of the disclosed method tracks or traces through permuted inverter gate structures to identify permuted correspondence;
[0052] Figure 6 is a circuit diagram of an exemplary functional connectivity template (“template”) on the lefthand side, including a NAND3 gate, and a circuit diagram of a portion of an exemplary search space (specifically, netlist) on the righthand side, illustrating that at least one embodiment of the disclosed method tracks or traces through permuted NAND gate structures to identify permuted correspondence;
[0053] Figure 7 is a circuit diagram of an exemplary functional connectivity template (“template”) on the lefthand side, including two PMOS devices, and a circuit diagram of a portion of an exemplary search space (specifically, netlist) on the righthand side devoid of a second PMOS device, illustrating that at least one embodiment of the disclosed method backtracks correspondences recorded when correspondence with a neighbouring template object is not obtained and / or validated;
[0054] Figure 8 is a circuit diagram of an exemplary functional connectivity template (“template”) on the lefthand side, including a NAND gate, and two circuit representations of different exemplary implementations of a NAND gate found in exemplary search spaces on the righthand side, illustrating that at least one embodiment of the disclosed method tracks or traces through expected NAND gate structures, as well as shorted NAND gate structures, to identify correspondence;
[0055] Figure 9 is a block diagram of an exemplary integrated circuit (IC) reverse engineering system, in accordance with a further aspect of the disclosure, which is operable to obtain imaging data from imaging at least a portion of an IC, process imaging data to generate netlist data, and compress netlist data by recognition of template occurrences and / or potential template occurrences in accordance with one embodiment of the method;
[0056] Figure 10 is a flowchart illustrating exemplary steps performable by an exemplary software product, in accordance with a further aspect of the disclosure, wherein a priori knowledge is inputted, and the software product carries out a method to compress netlist data based on predefined rules and any inputted a priori knowledge, and optionally to further refine the compressed netlist based on inputted postcompression parameters;
[0057] Figure 11 is a circuit diagram of an exemplary inverter, which was utilized as both the functional connectivity template (“template”) and the search space (ornetlist) in a run of an exemplary embodiment of the method disclosed herein, in order to generate an exemplary log trace; and
[0058] Figure 12, which is shown over Figures 12.1 to 12.5, is a reproduction of an exemplary log trace obtained from a run of an exemplary embodiment of the method disclosed herein, using the inverter of Figure 11 as both the template and the search space, illustrating the steps of the method in finer detail.
[0059] Elements in the several figures are illustrated for simplicity and clarity and have not necessarily been drawn to scale. Also, common, but well-understood elements that are useful or necessary in commercially feasible embodiments are often not depicted in order to facilitate a less obstructed view of these various embodiments of the present disclosure.DETAILED DESCRIPTION
[0060] Various implementations and aspects of the specification will be described with reference to details discussed below. The following description and drawings are illustrative of the specification and are not to be construed as limiting the specification. Numerous specific details are described to provide a thorough understanding of various implementations of the present specification. However, in certain instances, well- known or conventional details are not described in order to provide a concise discussion of implementations of the present specification.
[0061] Various apparatuses and processes will be described below to provide examples of implementations of the methods and systems disclosed herein. No implementation described below limits any claimed implementation and any claimed implementations may cover processes or apparatuses that differ from those described below. The claimed implementations are not limited to apparatuses or processes having all of the features of any one apparatus or process described below or to features common to multiple or all of the apparatuses or processes described below. It is possible that an apparatus or process described below is not an implementation of any claimed subject matter.
[0062] Furthermore, numerous specific details are set forth in order to provide a thorough understanding of the implementations described herein. However, it will beunderstood by those skilled in the relevant arts that the implementations described herein may be practiced without these specific details. In other instances, well-known methods, procedures and components have not been described in detail so as not to obscure the implementations described herein.
[0063] It is understood that for the purpose of this specification, language of “at least one of X, Y, and Z” and “one or more of X, Y and Z” may be construed as X only, Y only, Z only, or any combination of two or more items X, Y, and Z (e.g., XYZ, XY, YZ, ZZ, and the like). Similar logic may be applied for two or more items in any occurrence of “at least one ...” and “one or more...” language.
[0064] Unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure belongs.
[0065] Throughout the specification and claims, the following terms take the meanings explicitly associated herein, unless the context clearly dictates otherwise. The phrase “in one of the embodiments” or “in at least one of the various embodiments” as used herein does not necessarily refer to the same embodiment, though it may. Furthermore, the phrase “in another embodiment” or “in some embodiments” as used herein does not necessarily refer to a different embodiment, although it may. Thus, as described below, various embodiments may be readily combined, without departing from the scope or spirit of the innovations disclosed herein.
[0066] As used herein, the term “or” is an inclusive “or” operator, and is equivalent to the term “and / or,” unless the context clearly dictates otherwise. The term “based on” is not exclusive and allows for being based on additional factors not described, unless the context clearly dictates otherwise. In addition, throughout the specification, the meaning of "a," "an," and "the" include plural references unless the context clearly dictates otherwise. The meaning of "in" includes "in" and "on" unless the context clearly dictates otherwise.
[0067] The term “comprising” as used herein will be understood to mean that the list following is non-exhaustive and may or may not include any other additional suitable items, for example one or more further feature(s), component(s) and / or element(s) as appropriate.
[0068] The terms “sub-steps”, “step” and / or “steps” are used herein to facilitate comprehension of the various methods and are to be used interchangeably. As such, reference to a single step or sub-step may comprise multiple steps or sub-steps, and reference to plural steps or sub-steps may comprise a single step.
[0069] In this specification, the term “object” is used to describe any one or more of: a component or a connection between components, or the digital representation thereof. In specific embodiments, as the context will reflect, the term “object” refers to any one or more of a pin, a net, or an instantiated component in digital representation. The term “component(s)” may be used interchangeably with “node(s)”, “pin(s)”, “channels”, “terminal(s)” or the like, and the term “connection(s)” may be used interchangeably with “nets”, “edges”, “wires” or the like, in some embodiments.
[0070] In the reverse engineering of integrated circuits (ICs), the processing of data can become a constraint. In particular, when imaging of ICs is utilized to extract layout and / or connectivity data, imaging at such high resolution and image processing to extract data can be error prone and / or can exhibit relatively high levels of noise. Furthermore, as data obfuscation and / or masking becomes increasingly popular in IC design, extracting meaningful structural or layout data, particularly from IC layouts for which there is no or limited pre-existing information, can be challenging. The methods, systems and products described herein provide, in accordance with different embodiments, different examples which attempt to provide alternative solutions to existing IC data processing solutions, which for example can identify template structures even when attempts to obfuscate or mask circuitry are made.
[0071] Some embodiments of this disclosure may provide a manner to compress or reduce the IC data to be processed, thereby improving the speed at which computers may process the data and / or reducing the processing power required by computers to process the data. Indeed, the present disclosure may provide computationally efficient methods for identifying template occurrences in a digital object list data (or digital connectivity representation, or netlist) of at least a portion of an IC and for compressing the digital object list data prior to downstream processing. Generally, the methods, systems and products of this disclosure may achieve this by recognising one or more functional connectivity templates in a large dataset, and flagging or replacing templateoccurrences with unique identifiers to reduce the overall size of the dataset duringfurther processing. In some embodiments, the methods, systems and programs may be aided by a priori data of the template(s) and / or search space, although not all embodiments require same.
[0072] It is to be appreciated that the digital object list data mentioned above comprises components and connections therebetween (collectively referred to as “objects”), which are typically connected in a functionally relevant manner or otherwise connected in a manner to mask the true functioning thereof (e.g., by including additional unnecessary components or omitting components strictly unnecessary to function). It is to be further appreciated that the objects of the digital object list data can therefore be represented as nodes and edges, such as found in a graph, and therefore embodiments of the disclosure may rely on tracing or tracking of the digital object list data and / or the functional connectivity template(s) as graphs or similar representations, or indeed may be envisioned or exemplified as such. Notably, such tracing or tracking through objects be employed regardless of the representation of the object data (e.g., graphically, listed or otherwise).
[0073] In some embodiments, template recognition may be based on identifying occurrences of one or more functional connectivity template(s) (e.g., as structures) in the digital object list data. In embodiments employing graphic representation for the purposes of illustration, the functional connectivity template(s) may be represented as a template graph, and template matches may be identified in the digital object list data by representing the digital object list data as a search space graph of similar structure (see, for example, Figures 2 and 3). In these graphs, for example, nodes may represent the instantiated components, and edges may represent the nets which connect them. A template graph can therefore be searched for in the search space graph, by tracing or tracking through the search space graph, testing nodes and edges individually, to find correspondences of nodes and edges until a template match is obtained. Put another way, an isomorphic match can be searched for, wherein one or more structural equivalents of the template graph are searched for in the search space graph. The isomorphic match can be searched for by creating or assigning references for nodes and / or edges in any one or both of the template graph and search space graph, and generating correspondence by methodically identifying and testing neighbouring or adjacent nodes and / or edges in the search space graph against the template graph.Indeed, any correspondences so identified can be verified or confirmed based on subsequent correspondence between nodes and / or edges. In some embodiments, the graphs generated are not distant specific, and edges are not correlated with distances between components, or the like. These embodiments may, for example, simplify generation of correspondences, as only connectivity data or structure is traced or tracked to find identical matches, as opposed to spatial layout on the IC (or a portion thereof).
[0074] It is to be appreciated, however, that graph generation or searching is not requisite to the embodiments disclosed herein and searching particularly for graphic isomorphism is merely used above as one exemplary embodiment. Indeed, most embodiments disclosed herein parse or trace through a netlist as if it were a graph, without requiring any graphic conversion step or otherwise, as will become apparent.
[0075] In some embodiments, the methods, systems and products described herein provide for the tracing or tracking of connectivity between objects and can provide an identical match with templates (i.e., a 100% match, although such a match may depend on the template structure or characteristics, or search parameters, including allowing for permutable objects, recursive objects, dispensable objects and / or the like). Indeed, in many cases, this identical matching may be possible since many objects (if not most) have only two or three direct connections, thus the connectivity of most objects of a digital object list data does not fan out in high numbers. This is particularly true for embodiments where the digital object list data is a netlist. In some embodiments, the methods systems and products of the instant disclosure may thus allow for exact template matching. In this context, however, exact template matching may encompass identifying template occurrences based on rules of flexibility, which account for certain permutations which are generally allowable (for example, permutable objects), for objects forming part of components of high-complexity (for example, recursive objects), and for unexpected objects, such as those used in obfuscation, or missing objects, such as when objects are dispensable without departing from overall function (for example, dispensable objects), to name only a few examples of such flexible template matching provided.
[0076] It is to be appreciated that template searching in large datasets can be recursive and therefore computationally intensive in terms of memory and time. Thismay be particularly true where the dataset includes cyclic features. Therefore, some embodiments of the disclosure include assumption and validation procedures to avoid or at least ameliorate this. Some embodiments include unique method or step inhibitors, which strategically avoid the methods, systems and products described herein from carrying out unnecessary recursive testing, or otherwise expending processing time or power on searching paths for templates where, for example, a correspondence can easily be assumed and later validated. To provide one non-limiting example, such assumptions may be based purely on connectivity of objects (e.g., reverse connectivity), and later validated with object functional types and / or further object connectivity (e.g., forward connectivity). Some embodiments may avoid recursive searching using object markers, assigned to certain template object and / or search space objects, as will be herein described.
[0077] Broadly, the methods, systems and products described herein provide a general search procedure for identifying correspondence(s) between a functional connectivity template, or a plurality of templates, and digital object list data. This general search procedure may start with selecting or assuming a starting correspondence between a template object in the functional connectivity template and an existing IC object in the digital object list data, and thereafter attempting to validate the correspondence by moving to the next or neighbouring object in both the functional connectivity template and the digital object list data, to test for further correspondence therebetween. This process is iterated, with each movement to the next or neighbouring object resulting in a further selection or assumption of a correspondence to be validated. Correspondence is recorded either when there is no previously recorded correspondence for those objects, or because the new correspondence is equivalent to a previously recorded correspondence (i.e., not conflicting with previously recorded correspondence). Generally, iterations of the search or test procedure proceed in accordance with a predefined tracing cycle based on the type of dataset at hand. Where conflicting correspondences are obtained (i.e., correspondence for the object has been previously recorded and such correspondence is not equivalent to the new correspondence), the search procedure may involve backtracking or rewinding, by removing a preceding correspondence(s) and continuing the search seeking out alternative connection paths.
[0078] As such, in some embodiments, the testing may include tracking or tracing connectivity of components by moving from object (e.g., net, pin, or instantiated component) to neighbouring object (e.g., net, pin, or instantiated component). Testing may thus involve identifying or retrieving neighbouring objects from the functional connectivity template (“template”) and / or the digital object list data (“search space”). Such identification or retrieval of neighbouring objects from the respective lists may be performed in accordance with methods known in the art. For example, neighbouring objects may be identified or retrieved using a database query, a memory lookup, or the like. Identifying the neighbouring objects may include enumerating the neighbouring objects in the template and the search space. As noted above, such tracking or tracing proceeds in accordance with the predefined tracing cycle, that being a recognisable sequence based on typical IC design in this instance. In particular, the tracking or tracing sequence may track or trace from instantiated component, to pin, to net, to instantiated component, to pin, to net and so forth. In some specific embodiments, tracking or tracing may proceed in a clockwise direction, or otherwise in a logic-based tracking operation, to ensure no instantiated component, pins or nets are overlooked during the tracking or tracing.
[0079] In preferred embodiments, the tracking or tracing may proceed in a depth- first manner, as described herein. Such depth-first tracking or tracing may proceed, for example, with one neighbouring object at a time until such time as a correspondence cannot be validated and provided no other rules disposing of validation are implemented, when the tracking or tracing may backtrack through objects previously tracked or traced through, before retesting alternative object paths, in order to find an alternative path of correspondences which can be validated. Put differently, the method will backtrack correspondence(s) and attempt to find a different pair of objects for which a correspondence can be successfully formed. Notably, it is within such tracking or tracing that one advantage of the instant disclosure may be present. In particular, since tracking or tracing of objects may include cyclic design features, or include nets with a multitude of repeated objects, certain aspects of the instant disclosure account for these features or repetitions, as described elsewhere herein.
[0080] In some embodiments, certain search space objects may be regarded as highly complex or recursive, and therefore may be considered to correspond withrelevant template object(s) without testing each and every neighbouring (or downstream) object of the search space object regarded as complex or recursive. As such, embodiments disclosed herein may avoid computationally extensive recursive searching when search space objects have been previously identified as potentially causing such a consequence. In some embodiments, these search space objects may be specifically assigned with a recursive-object marker, such that when this object is tested for correspondence, there is an assumption of downstream object correspondence, thereby avoiding recursive searching.
[0081] In some embodiments, certain template objects may be regarded as dispensable, such that template matches may be located in the search space regardless of one or more objects or devices being omitted (or improperly identified) in the search space. As such, embodiments disclosed herein may allow for strictly structurally inexact matching in the case of a template object being missing from the search space. However, this matching is still considered exact matching in this context, based on testing rules applicable to objects assigned with a dispensable-object marker, as will be described herein.
[0082] In some embodiments, certain template objects may be regarded as permutable, such that template matches may be located in the search space despite objects being transposed, for example, in the search space. As such, embodiments disclosed herein may allow for template matching in the case of a search space possibly reflecting templates with possible input or imaging errors, or identification errors, in the case of reverse engineering ICs, and indeed may provide a template matching method which recognizes the permutability of certain objects in such cases.
[0083] Notably, the methods, systems and products described herein may attempt to identify template occurrences in a search space by recording tracking or tracing through objects, as described above. A template object may be considered produced where (i) a search space object is found to correspond with the template object (i.e., correspondence identified), and (ii) search space object(s) are found to correspond with all neighbouring template object(s) of the template object (i.e., correspondence validated). As such, successful correspondences between neighbouring objects validates the correspondence of the initial object. Accordingly, correspondences and validation thereof is based on tracking or tracing connectivity of components. As aconsequence of the structure of ICs, recursion is inherent in this correspondence search procedure, which facilitates validation and where necessary, can be inhibited to avoid overly intensive searching, as described herein.
[0084] We now turn to providing non-limiting examples of the implementation of these general principles into certain embodiments of the methods, systems and products of the instant disclosure.
[0085] With reference to Figure 1, and in accordance with one exemplary embodiment, a computer-implemented method of digitally compressing a digital connectivity representation of at least a portion of an IC, generally referred to as “the method” and using the numeral 10, will now be described. It is to be appreciated that steps of the method 10 may be described separately herein for purposes of illustration, but upon implementation may be combined into single steps, as appropriate. At 12, the method 10 commences.
[0086] At 14, the method 10 comprises providing or otherwise accessing a functional connectivity template (“template”). The template comprises a combination of objects, components and their connections, to be searched for in a search space. In particular, the template at least comprises template integrated circuit objects and respectively associated object functional types. In this embodiment, although not specifically shown, the template represents a functional device which is expected in / on an IC, and therefore represented in a netlist. In other embodiments, templates may comprise predetermined IC structures, devices or portions thereof, known or suspected to be present in the IC or portion thereof. The template typically includes 10s of objects, although larger templates may include 100s or 1000s of objects (or even more) in other embodiments. In other embodiments, the template may be provided or accessed together with other templates (i.e., a plurality of templates may be provided or accessed). In some embodiments, the template may further include one or more object markers associated with one or more objects, the markers being recognizable by a processor during execution of the method 10 such that one or more test rules are applied when testing for correspondence of objects being so marked. Markers may be preassigned to one or more objects of the template, and / or may be assigned by a user to search space objects at any stage. The use of object markers in some embodiments of the method are described below.
[0087] At 16, the method 10 comprises receiving or accessing the digital connectivity representation of at least a portion of the IC (“search space”). The search space comprises a list or graph of objects to be searched for any or all occurrences of the template. More specifically, the search space comprises digital object list data representative of components and connections therebetween on the IC, and at least comprises existing integrated circuit objects (“search space objects”) and respectively associated object functional types. In this particular example, the digital object list data is raw netlist data obtained from an image extraction module operable to extract netlist circuitry from one or more high resolution images of the IC. The digital object list data is this example has thus not undergone any pre-processing steps (e.g., to partition pins and nets, or to partition p- and n-type devices, or the like). Thus, the digital object list data or search space is a netlist extracted for at least a portion of the IC, and occurrences of the template are to be searched for therein.
[0088] In this particular embodiment, the digital connectivity representation or search space comprises a netlist and the functional connectivity template defines a digital logic cell. It is to be appreciated that the netlist received at 16 comprises a list of the components and connections therebetween on the IC, or otherwise comprises identifiers associated with such components and connections. More specifically, the template integrated circuit objects and the existing integrated circuit objects comprise any one or more of: a pin, a net, or an instantiated component. In some embodiments, the netlist may include further properties of components or otherwise, indicators of larger devices and properties. Indeed, the netlist may take any form known in the art.
[0089] At 18, this searching commences, whereby the method 10 comprises recording a first correspondence between a first template integrated circuit object of the template and a first existing integrated circuit object of the search space. In this embodiment, at 18, the step of recording the first correspondence comprises assuming the first correspondence. In particular, the first correspondence between a template object and an existing object may be assumed based on, for example, an existing integrated circuit object having the least number of occurrences in the digital object list data; or an existing integrated circuit object identified as being connected to a predefined component in the digital object list data. By starting with an existing object having the least number of occurrences, there may be a higher probability of finding acorrespondence in a shorter timeframe. By starting with an existing object identified as being connected to a predefined component, there may be a greater chance of successful tracking or tracing at least through the predefined component.
[0090] The first correspondence is recorded at 18 provided it does not conflict with any previously recorded correspondence. This first correspondence is, in this embodiment, based on matched object types (i.e., the search space object with the template object, as described below with reference to the second correspondence), but in other embodiments is based on other properties integral to the object, such as name, label, type, functionality, connectivity to other objects (or objects having the foregoing properties), or the like, or yet otherwise a combination of properties. Notably, this first correspondence is identified between any template object and corresponding search space object, and is assumed provided that no existing correspondence for either the template or search space object has been recorded (and therefore the first correspondence so assumed does not conflict with any previously recorded correspondence). In some embodiments, however, this first correspondence is based on certain predetermined first assumption rules (e.g., objects of least complexity, or objects visually identifiable). The first correspondence is recorded in a correspondence table, or otherwise stored in memory in another suitable format. To record the correspondence, in this embodiment, both the template object and search space object are assigned simple numerical indicators, which require no computation or algorithmic execution to generate, except for tracking increments (in other embodiments, other strings or the object names may be used i.e., template object “Inst inv_nl” == search space object “Inst inv_nl0”). Yet further, to associate this correspondence with the objects themselves, an object field of each object, in the template and in the search space, is used to point or refer to the other by means of the corresponding numerical indicator, and vice versa. Where objects have yet to be recorded to correspond to other objects, those objects fields will be NULL.
[0091] At 20, the method 10 comprises testing a neighbouring existing integrated circuit object of the search space against a neighbouring template integrated circuit object of the template for a second correspondence therebetween, wherein further steps of the method 10 are dependent on the outcome of this testing 20. Notably, the testing stage 20 comprises various sub-steps, which are described here although not separatelyshown in Figure 1, before proceeding to any one of: recording the second correspondence at 22, or searching for a different neighbouring search space object at 32.
[0092] In this embodiment, testing the neighbouring object at 20 (and further neighbouring objects in due course) includes attempting to produce correspondence between the neighbouring template object and a neighbouring search space object. The method, at 20, thus includes identifying the neighbouring template object. Identifying the neighbouring template object proceeds, in this example, in accordance with a predefined tracing cycle, such that an instantiated component is identified, before a pin is identified, before a net is identified, and so forth, in a depth first manner. If multiple neighbouring objects are identified, and if the multiple neighbouring objects are all pins, testing proceeds first with G pins, then S pins and then D pins. Notably, this predefined tracing cycle may differ in different embodiments or applications. The method, at 20, also includes identifying a neighbouring search space object. As neighbouring obj ect(s) are identified by the method 10 in the template and search space, the method 10 assigns the neighbouring object(s) a simple numerical indicator, incremented from the previous object indicators. Notably, indicators assigned to each object in the template and search space are unique to that object and are intended to provide a simple object reference system for recordal of correspondence (although utilizing object names is also workable, as mentioned).
[0093] Once the neighbouring template and search space objects are identified, testing 20 for correspondence between the neighbouring template object and the neighbouring search space object is based on at least matched object functional types in this example. For example, if the neighbouring template object is an instantiated component, then the neighbouring search space object should also be an instantiated component for there to be correspondence. The same matched object functional types would need to be present with pins and nets. Notably, in different embodiments, testing 20 may further include verifying such correspondence at this stage based on other properties or data associated with objects, including for example, matched instantiated component type (transistor, resistor, capacitor, inductor etc.), matched pin type (source, gate or drain), or matched net type (power or ground), as the case may be, depending on the fine tuning required. In this particular embodiment, testing for matching objectfunctional types comprises (i) comparing the object functional types of the neighbouring template object and the neighbouring search space object; and (ii) if the object functional types are matched, verifying the match based on the particular object functional type (instantiated component, pin or net) and / or stage of the tracing cycle. In this example, if the object functional types of the search space neighbouring object and the neighbouring template object are the same (i.e., both are instantiated components, both are pins, or both are nets), the object functional types are said to be matched, and such match is then verified based on the particular matched object functional type. Broadly, four categories of such verification are identified: verifying correspondence for a generic instantiated component, verifying correspondence for a pin from an instantiated component (looking out to a net), verifying correspondence for a net, and verifying correspondence for a pin from a net (looking out to an instantiated component). Each of these four verification tests for finding correspondence will now be described, although not shown in Figure 1 specifically.
[0094] To verify correspondence for an instantiated component, the method 10 includes verifying that the instantiated component type of the search space object matches the instantiated component type of the template object. For example, if the instantiated component in the template is a resistor, the instantiated component in the search space must also be a resistor. This verification in the case of instantiated components need not be strict, and indeed matches which are not identical may suffice, depending on thresholds or other parameters pre-set by users and received by the method 10 in an earlier step. For example, an NMOS type of instantiated component in the template could match any MOS device in the search space. Such verification flexibility in instantiated component type may be useful, for example, where the search space (i.e., reversed engineered netlist) does not contain transistors characterized by their N or P subtypes. Indeed, this verification flexibility may be pre-set by a user based on the level of data available in the search space (e.g., reverse engineered netlist may not contain N or P subtypes, thus NMOS devices may be set to match any MOS device in search space, in an earlier step of the method 10).
[0095] To verify correspondence for a pin from an instantiated component (looking out to a net), the method 10 includes verifying that the pin type in the search space matches that of the pin type of the template pin. This verification in the case of pinsagain need not be strict, and indeed matches which are not identical may suffice, depending on thresholds or parameters pre-set by users. For example, in a strict verification of pins, a MOS Pin S in the template can only be verified to correspond to a MOS Pin S in the search space. In a more relaxed verification of pins, the method may regard MOS S Pins and MOS D Pins as one type (i.e., a channel connection) and thus capable of correspondence. As such, a MOS Pin S in the template can match to either a MOS S Pin or a MOS D Pin in the search space, since the method is really searching for a channel connection which may be either. Note that the same may generally hold true for resistors and capacitors (PLUS and MINUS), in different embodiments, and that the method 10 may relax verification to facilitate template recognition.
[0096] To verify correspondence for a net (from a pin), the method 10 includes identifying whether the net in the template is a power net or a ground net and, if it is a power net or ground net, verifying whether the net in the search space is also a power net or a ground net (i.e., net types must be matched). If the method 10 verifies that the net type is the same, a valid correspondence can be assumed (i.e., without testing further neighbouring objects of the net). If the method 10 identifies that the net in the template is not a power net or a ground net, the method 10 may assume correspondence between the template net and search space net, simply by the fact that the search space net exists (i.e., and not ensuring that the net types necessarily match, nor testing further neighbouring objects of the net).
[0097] To verify correspondence for a pin from a net (looking out to an instantiated component), the method 10 includes verification of pin type steps similar as to described above (for finding correspondence for a pin from an instantiated component).
[0098] For the sake of simplicity, in continuing the exemplary method 20 with reference to Figure 1, it is irrelevant which object type was matched and / or verified, but it is relevant that the neighbouring template object and the neighbouring search space object matched in type, and the matched type was successfully verified based on the above parameters, such that a new correspondence (i.e., a potential second correspondence) is identified.
[0099] Next, the testing 20 stage of the method 10 proceeds to determining whether the new correspondence, the potential second correspondence, between this template and search space object conflicts with any previously recorded correspondence. As such, the method 10 includes searching for or retrieving any previously recorded correspondences for those objects, to determine whether there is a conflict. As noted, object fields will be NULL if there is no previously recorded correspondence or otherwise, will have a pointer or indicator to a corresponding template / search space object if correspondence has been previously recorded. In some embodiments, the method (not shown), and therefore further search, will be discontinued if the identified correspondences have already been recorded.
[0100] The new correspondence, the potential second correspondence, is deemed to conflict with a previously recorded correspondence where either one of the template or search space object (or both) has a previously recorded correspondence which is different from the new correspondence. Put differently, such conflict typically occurs where correspondence for the template and / or search space object has already been recorded, and the new correspondence is not equal thereto. If the new correspondence conflicts with any previously recorded correspondence, the method 10 does not record the new correspondence (or if the new correspondence is committed to memory, it is removed) such that no second correspondence is recorded. Since the new correspondence is not recorded or is removed, the search method 10 proceeds to retest for a neighbouring search space object (i.e., step 32) which may correspond to the template object, based on matched object functional types, as described above and in accordance with the tracing cycle. If none exists, the method 10 will backtrack or rewind by removing correspondences previously recorded and searching again (backtracking procedure described further below).
[0101] The new correspondence (the potential second correspondence) is deemed to not conflict with previously recorded correspondences where either (1) no previously recorded correspondences for those objects exist; or (2) where previously recorded correspondences for those objects do exist, but these do not conflict with the new correspondence. If the new correspondence does not conflict with any previously recorded correspondences, the method 10, at 22, records such new correspondence as a second correspondence. Notably, recording the second correspondence may compriseconfirming the previously recorded correspondence in embodiments where they are equal, else recording the second correspondence may comprise entering the second correspondence (in a correspondence table or to memory) afresh in embodiments where there is no previously recorded correspondences for those objects. As noted above, in this particular example, recording the first, second and / or subsequent correspondences in the case of the latter comprises (i) recording correspondence of the numerical indicators assigned to each object; and (ii) using a single field on each of these objects (in template and in search space, as allocated in memory), where the field is a pointer to the corresponding object. In this example, the object field is NULL or empty if no correspondence has been previously recorded. Indeed, such pointer-based correspondence recording may remove the need for hash tables or the like, in this example. Returning to recording the second correspondence at 22, it should be noted that such correspondence recordal may also be considered a correspondence assumption (although being verified), which is subject to further validation through correspondence of further neighbouring objects (as described with reference to the second correspondence validating the first correspondence below).
[0102] In this embodiment, if the second correspondence does not conflict with any previously recorded correspondence, and thus is recorded at 22, the method 10 comprises validating the first correspondence. Put differently, the first correspondence between the template object and the search space object is said to be validated since its downstream connection in both the template and search space, the neighbouring template object and neighbouring search space object, also correspond (although this second correspondence should also still be validated based on its further connectivity). In order for the correspondence between the neighbouring objects to be validated, a further testing iteration would be required to test for correspondence between further neighbouring objects, and so forth.
[0103] Therefore, it is to be appreciated that the conflict test portion of testing 20 for correspondence between a template object and a search space object (including identifying / determining conflicts and / or recording the correspondence), can be considered to define four different possible conflict testing implementations. The conflict testing implementation utilized by the method 10 is based predominantly on whether or not the template object and search space object have previously recordedcorrespondences, and if so, whether the correspondences are equal. In a first conflict testing implementation, the method 10 identifies that both the template object and the search space object have previously recorded correspondence. In this implementation, the method 10 compares the new correspondence against the previously recorded correspondence for the template object and against the previously recorded correspondence for the search space object to determine whether they are equal (and not conflicting) or not (and conflict). If the new correspondence for the search space object is equal to the previously recorded correspondence for the search space object, then method 10 recognises that this correspondence has already been recorded and therefore retains it (allowing the method 10 to proceed to testing further neighbouring objects). If the new correspondence for the search space object is not equal to the previously recorded correspondence for the search space object, then the new correspondence cannot hold true and so is not stored and / or is removed from memory (recall that template objects cannot correspond to two or more different search space objects in a single run). In a second conflict testing implementation, the method 10 identifies that the template object has no previously recorded correspondence but the search space object does have a previously recorded correspondence. In this implementation, the method 10 identifies that the search space object has already been found to correspond to a different template object and therefore the new correspondence cannot be recorded (recall that one search space object cannot correspond to more than one template obj ect). In a third conflict testing implementation, the method 10 identifies that the template object already has a previously recorded correspondence and the search space object does not yet have any recorded correspondence. In this implementation, the method 10 identifies that the template object has already been found to correspond to a different search space object and therefore the new correspondence cannot be recorded (recall that one template object cannot correspond to more than one search space object in a single run). In a fourth conflict testing implementation, the method 10 identifies that both the template object and the search space object do not have any previously recorded correspondence recorded against them. Since there are no previously recorded correspondences for either, there are no conflicts, and the new correspondence can be recorded against both the template and search space objects (note that this will be later validated by finding correspondence between any and all neighbouring objects).
[0104] Notably, with reference to the tracing cycle by which testing 20 proceeds, it is to be appreciated that certain neighbouring objects can be expected due to the functional design of an IC, and therefore can be readily identified based on the tracing operation or cycle. For example, the neighbouring objects of instantiated components are pins, and these pins can be identified and assigned numerical indicators (or simply enumerated) by the method 10 by grabbing the listed of pins associated with a given instantiated component for further testing. Further, the neighbouring objects of pins from an instantiated component are nets, and these nets have a 1 : 1 relationship with pins. Thus, the net associated with the given pin from an instantiated component can be readily identified and assigned a numerical indicator by the method 10 for further testing. Further, the neighbouring objects of these nets are pins, and each net may have multiple pins which can be identified and assigned numerical indicators (or simply enumerated) by the method 10 by grabbing the listed of pins associated with a given net for further testing. Yet further, the neighbouring objects of these pins (from a net) are instantiated components, and these pins have a 1 : 1 relationship with the instantiated components to which they belong. Thus, the instantiated component associated with the given pin can be readily identified by the method 10 for further testing in accordance with the tracing cycle.
[0105] In summary, if during or as a result of testing 20, the neighbouring search space object is found to correspond with the neighbouring template object (having matched object types and having been successfully verified), and such correspondence does not conflict with any previously recorded correspondence, the second correspondence is recorded at 22, thereby validating the first correspondence.
[0106] At 24, the method 10 determines whether correspondence has been found for all template objects in the search space. Put differently, at 24, the method 10 determines whether the recorded correspondences (and as such, validated) reflect correspondence between two or more search space objects against all corresponding template objects in the template. If not, the method 10 returns to step 20 to test further neighbouring obj ects for further correspondence. In particular, when method 10 returns to step 20 from step 24 after validating a first correspondence, the testing 20 is to test for correspondence between a neighbouring template object in the template and a neighbouring searchobject in the search space to identify a further correspondence, which in turn would validate the second correspondence.
[0107] If the method 10 determines at 24 that correspondence has indeed been found for all template objects in the search space, the method 10 proceeds to 26, to registering an occurrence of the template in the search space. In this particular embodiment, registering 26 the occurrence comprises flagging the two or more existing integrated circuit objects in the digital object list data with a digital identifier representative of the component connectivity template. In other embodiments, other means of registering the occurrence of the template may be employed to facilitate compression of the netlist.
[0108] In this embodiment, upon registration of the occurrence of the functional connectivity template at 26, the method 10 comprises at 28, determining whether the remainder of the search space has been searched for further occurrences of the template. If so, the method 10 proceeds to terminate at 30. If not, the method 10 returns to repeating steps of recording 18 and testing 20 to identify any further occurrences of the functional connectivity template in the digital object list data. When this occurs, the existing integrated circuit objects in the digital object list data registered to correspond with the functional connectivity template (specifically, flagged) are not included or searched in subsequent steps of recording 18 and testing 20. As such, it is to be appreciated that the method 10 repeats searching for occurrences of the template in the search space, even if one or more template occurrences have been identified in previous iterations, until all search space objects (components and connections) have been tested. Indeed, occurrences of the template in the search space may be numerous, and therefore searching is iterated to identify any and all such template occurrences to optimize compression of the netlist.
[0109] As noted, if during testing 20, the neighbouring search space object is found to not correspond with the neighbouring template object (based on distinct object functional types, matched object functional types not being successfully verified, or otherwise if the new correspondence conflicts with any previously recorded correspondence), the method 10 comprises at 32, searching for a different neighbouring search space object against which to test the neighbouring template object. If a different neighbouring search space object is identified (which has not been tested previously), the method 10 returns to testing 20 that different neighbouring search space objectagainst the neighbouring template object for correspondence. If a different neighbouring search space object is not found, or does not exist, the method 10 comprises, at 34 in this embodiment, determining whether the preceding correspondence was the first correspondence, or a second or subsequent correspondence. If the preceding correspondence was the first correspondence, the method 10 removes the preceding correspondence from the recorded correspondences and then returns to recording 18 a new first correspondence. If the preceding correspondence was the second or further correspondence, the method 10 removes the preceding correspondence from the recorded correspondences and returns to testing 20 to identify further neighbouring objects for testing.
[0110] In this embodiment, therefore, the step of testing 20 is repeated for at least one more neighbouring existing integrated circuit object of the digital object list data. In some embodiments, testing 20 is repeated for all existing integrated circuit objects of the digital object list data, attempting to find respective correspondences with template objects.[OHl] In this embodiment of method 10, both of the first correspondence and the second correspondence comprise at least matching object functional types. In particular, when recording 18 the first correspondence, or testing 20 to find the second correspondence (or subsequent correspondences), the method 10 comprises identifying an existing object in the object data list (either the first existing object, or a neighbouring existing object) and comparing the object functional type of the existing object to the object functional type of the relevant template object (either the first template object, or a neighbouring template object). If the object functional types match, the method 10 may recognise this as a correspondence (a first correspondence or a second correspondence, as the case may be). In some embodiments, object functional types may include, for example, discrete object functional types and permutable object functional types. In some embodiments, discrete object functional types are associated with objects for which identical object matching is required. For example, discrete object functional types may include power nets. Permutable object functional types may be associated with objects for which permutable object matching is possible. For example, permutable object functional types may include source and drain pins / channels in a MOS device (described in further detail below). Otherwise, inother embodiments, the object functional types may not distinguish between discrete and permutable types, but instead may involve the application of markers which identify permutable objects as being permutable. In some embodiments, correspondence may include, or even require, the matching of other attributes. The attributes may include transistor type (e.g. p-type, n-type), size matching (or ensuring that potentially corresponding objects are within calculated or pre-determined size parameters), or the existence of user- or Al-generated generic tags to be associated with objects. For example, such user generated tags could be associated to observed characteristics that may provide an indication of functionality or other attributes, such as whether an functional object include an “extended drain area” (which, generally speaking, is when a longer connection is used in association with a drain thereby causing it to behave like a resistor or have resistive characteristics), is part of power domain, has certain observable or assumed gate oxide characteristics, has wellconnection bias, or indeed any observed, automatically determined, or assumed characteristics, or even an arbitrary user-generated tag.
[0112] In this embodiment, testing 20 the neighbouring existing integrated circuit object comprises applying a permutation rule if the neighbouring template integrated circuit object is of a permutable object functional type. In one embodiment, the permutation rule comprises assuming a permuted correspondence between the neighbouring existing integrated circuit object and the neighbouring template integrated circuit based on the permutable object functional type. Due to the nature of permutable object functional types, an object having a permutable object functional type is associated with a complimentary object having a complimentary permutable object functional type. As such, in this embodiment, testing 20 a further neighbouring existing integrated circuit object comprises applying the permutation rule to the further neighbouring existing integrated circuit object. Put differently, the permutation rule is applied to both template objects which are permutable.
[0113] In this embodiment, therefore, the method 10 allows for the searching of zero or more occurrences of the template in the netlist. For example, method 10 may search for zero or more resistors in the netlist. Such zero or more searching may increase the error-tolerance of the method 10, which may be particularly useful when an IC is to bereverse-engineered; and may be one distinguishing feature over verification procedures which require devices to be identified.
[0114] In this embodiment, the depth-first approach of method 10 means that the method 10 and its search procedure is not limited to identifying template occurrences within boundary boxes. Indeed, in this embodiment, no such boundary boxes need be defined, since the method 10 tests neighbouring objects in a depth-first, step-by-step approach, backtracking when necessary, to identify template occurrences.
[0115] Notably, the above method 10 does not require grouping or partitioning of the existing objects in the digital object list data (or search space) based, for example, on device type (i.e., p- or n-type), and indeed does not require data which identifies p- or n-type transistors, for example. This may be one reason why the methods of the instant disclosure are useful for reverse engineering ICs, where such data may not be available or requires tedious processing to extract such as, for example, from images of the IC. Nevertheless, embodiments wherein p- and n-type are available upfront and are utilized in method 10 are also envisaged.
[0116] Yet further, the above method 10 does not require complex labeling computation or identifier marking of the existing objects in the digital object list data upfront in order to proceed with the method 10. Instead, correspondences may be recorded by means of references if and when such correspondences are identified, and correspondences may be retained only if validated (unless a validation rule permits omission of validation), thereby allowing execution of the method 10 without complex or memory-intensive labelling procedures.
[0117] Furthermore, the above method 10 does not require a further verification procedure, such as bit-based verification, since the depth-first approach leads to later recorded correspondences validating earlier recorded correspondences without additional verification. Similarly, assumed correspondences or permuted correspondences (which are arguably also assumption-based) are validated based on subsequently recorded correspondences without further verification procedure(s).
[0118] Once all occurrences of the functional connectivity template in the digital object list data have been identified or, put differently, once all existing integratedcircuit objects in the digital object list data have been tested against the functional connectivity template, the method terminates at 30.
[0119] It is to be appreciated that various alternative embodiments of the method 10 are envisaged, as well as various alternative embodiments of the testing stage 20 in particular, without departing from the general nature and scope of the instant disclosure. Some of these embodiments or variations are briefly described hereunder.
[0120] In some embodiments, the method comprises a step of receiving an object identification marker assigned to a particular existing integrated circuit object of the digital object list data. In embodiments where this step is included in the method, the step of testing the neighbouring existing integrated circuit object further comprises identifying whether the object identification marker has been assigned to the neighbouring existing integrated circuit object. If the neighbouring existing integrated circuit object corresponds with the neighbouring template integrated circuit object, and if the object identification marker is assigned to the neighbouring existing integrated circuit object, the method comprises a step of assuming correspondence of any downstream objects of the neighbouring template integrated circuit object. The step of assuming correspondence of any downstream objects comprises recording a correspondence (sometimes referred to as an “assumed correspondence”) between the neighbouring existing integrated circuit object and the neighbouring template integrated circuit object, and not testing any objects neighbouring the neighbouring existing integrated circuit object assigned with the object identification marker. Put differently, after an assumed correspondence based on identifying an object identification marker, the method may not be carried out on further neighbouring objects in the netlist (or search space). In some embodiments, the assumed correspondence may therefore be representative of the object having assigned thereto the object identification marker, as well as any downstream or neighbouring objects.
[0121] In one embodiment, the object identification marker is assigned to one or more existing integrated circuit objects when known to be of high complexity, or at least a part of an integrated circuit component of high complexity. In this context, “high complexity” may be used to refer to objects which are connected to a large number of components, relative to the typical amount of connections to components in an IC. For example, if a typical number of connections is two or three, an object of highcomplexity may be an object being connected to three or more components. Put differently, objects of high complexity may be those known to present a fanout of components.
[0122] Since the assumed correspondence is recorded, it should be appreciated that any further correspondences recorded should not conflict with this assumed correspondence. Further correspondences recorded should validate the assumed correspondence (put differently, further correspondences prove consistency of previously recorded correspondences). If a conflict arises, the method will backtrack, as herein described, until the conflict is resolved. As such, in these embodiments, the method may provide a solution or at least ameliorate the computational complexity required when tracing or tracking through components with high complexity.
[0123] In some embodiments, the particular existing integrated circuit object(s) of the digital object list data to which the object identification marker(s) is visually identified. The relevant object(s) may be identified, for example, by IC engineers studying the IC or a portion thereof, and having knowledge of typical IC components and / or connections. In some embodiments, the particular existing integrated circuit object(s) may be, for example, a power net(s). In some embodiments, power nets may fan out to hundreds of connected components. The method, upon identification of the object identification marker assigned to the existing power net object in the digital object list data, records an assumed correspondence and does not carry out testing 20 for further objects neighbouring the power net object. As such, the method does not involve continuing testing 20 of each component or connection connected to the power net. Indeed, many components can be connected to a power net, presenting a fan out which would be computationally intensive to carry out testing 20 for. By marking components, such as power nets, known to be of high complexity, beforehand, the method 10 is prevented from carrying out computationally intensive and potentially recursive search paths. It is to be appreciated, however, that should further template objects require correspondence to the power net already recorded, those objects should exhibit a one-to-one correspondence with the power net. For example, one embodiment of an IC may include one ground net, and four or five different power nets. In such an example, the different power nets should only correspond to one object in the recorded correspondences. In some embodiments, power nets and ground nets may be treated asspecial nets, collectively referred to as supply nets. In particular, supply nets may be used in an initial iteration of the method, such as to serve as the starting point for the first assumption.
[0124] In some embodiments, different existing objects may receive different object identification markers, wherein the marker reflects the object-type associated with the existing object.
[0125] In one embodiment, the object identification marker comprises a dispensable-object marker. The method 10 comprising a step of receiving the dispensable-object marker assigned to a given template integrated circuit object of the functional connectivity template. In this embodiment, if the neighbouring template integrated circuit object is assigned the dispensable-object marker, and if no neighbouring existing integrated circuit object if found to correspond with the neighbouring template integrated circuit object (i.e., is omitted, missing or improperly identified), a previously recorded correspondence is still validated. In some embodiments, the dispensable-object marker is assigned to one or more template integrated circuits objects based on predicted shorting patterns. In other embodiments, the dispensable-object marker is assigned to one or more template integrated circuits objects known to be disposable without altering functioning of a device. To provide one non-limiting example, where the functional connectivity template comprises an AMP, it is well known that many IC designers include, generally, a two-terminal device, including, e.g., capacitor, resistor, diode, (but may include other types, such as transistor or other functional objects having more terminals), which is not requisite to the functioning of the AMP. The method 10 may include the dispensable device, assigned or marked with the dispensable-object marker, such that during testing, a correspondence can be obtained and verified despite the dispensable device not being present in the digital object data list (search space). This dispensable-object marker may also be considered a dispensable-object rule (or a missing device rule), in different embodiments. In yet other embodiments, the dispensable nature of an object(s) may be inherent to the object functional type, or object name. Accordingly, these embodiments allow for exact matching to templates even where potential structural deviations are encountered. It is to be appreciated that the vice-versa of this rule may also be implemented, for example to identify matches wherein additional objects (additional tothat of the template) are present in the digital object data list. In some embodiments, the dispensability of an object may be pre-defined, forming part of the functional connectivity template, and in other embodiments the dispensability of an object may be defined during execution of the method 10, for example, as inputted by a user.
[0126] In some embodiments, each existing integrated circuit object in the digital object list data has a single occurrence in the recorded correspondences. Indeed, the recorded correspondences may be said to reflect one-to-one correspondence of the existing integrated circuit objects in the digital object list data. It is to be appreciated, however, that the recorded correspondences may include several occurrences of template objects, depending on the number of occurrences of the functional object template in the digital object list data, with different occurrences of the templates (or template objects) being relabeled to reflect separate occurrences.
[0127] In some embodiments, it may be advantageous to flatten a netlist received. For example, if a netlist is received as a hierarchical netlist, with connections grouped in some manner, flattening this netlist out to provide a netlist in which all connections are shown may be considered. Such flattening out may be considered counterintuitive to those skilled in the art, since further connections proportionately increases processing required. However, in some embodiments of the present disclosure, such flattening out may indeed be required for the testing 20 phase, particularly to obtain one-to-one correspondence between objects in the template(s) and netlist. Thus, in some embodiments, the netlist may comprise a string representative of the connectivity of components of the IC (or a portion thereof). In such embodiments, since the digital connectivity representation comprises a netlist, and since testing involves tracking or tracing through the netlist, this testing may be regarded as parsing of the netlist, with identifiable digital logic cells (based on functional connectivity templates) being identified and labelled or flagged (e.g., with a unique template identifier). Put- differently, in some embodiments the method may comprise a grammar-based search.
[0128] In some embodiments, the IC is an existing IC, and the computer- implemented method comprises a preliminary step of deriving at least a part of the digital connectivity representation from one or more images of the IC. Methods for deriving the digital connectivity representation from images of the IC may include those already forming part of the art.
[0129] In other embodiments, registering the occurrence may comprise replacing the two or more existing integrated circuit objects in the digital object list data with a digital representation of the component connectivity template. Indeed, any mechanism or manner of registering the occurrence of the template in the object data list may be used, provided the registering may be useful to reduce the overall size of the object data list, or otherwise reduce the processing power required to process the object data list, or the like.
[0130] In some embodiments, the method allows for template recognition with minimal user input.
[0131] In some embodiments, the functional template may be stored and / or tested in a predefined production order. The predefined production order may follow logic rules or otherwise, may be structured to seek correspondences in a relatively efficient manner. For example, the predefined production order may commence with gate pins, followed by source pins and then drain pins. As such, at 18, recording the first correspondence may comprise assuming the first correspondence based finding a matching object type based on the first object of the functional template to be tested based on the predefined production order.
[0132] In other embodiments, the method 10 comprises receiving a plurality of functional connectivity templates, or otherwise retrieving a plurality of functional connectivity templates as previously received and stored. In such embodiments, each of the plurality of functional connectivity templates defines a different digital logic cell. In some embodiments, the plurality of functional connectivity templates may comprise twenty-six templates, each representing a different digital logic cell.
[0133] In some embodiments, method 10 is distinguishes between internal and external nets in the template. In particular, method 10 may allow for recording of correspondences between two external nets in the functional connectivity template and a single net in the digital object data list. Such distinction between internal and external nets, and recognition of correspondences between two external nets in the template and a single net in the digital object data list may allow for the recognition of shorted nets, for example. In one particular embodiment, method 10 comprises receiving a net- location marker assigned to one or more template integrated circuit objects, wherein thenet-location marker is either an intemal-net marker and an extemal-net marker. In this particular embodiment, testing 20 comprises determining if two given template integrated circuit objects each assigned the extemal-net marker correspond to a single existing integrated circuit object, such that shorted nets can be identified. Indeed, such correspondence will be later validated based on subsequently recorded correspondences, or otherwise backtracked (for retesting) if no further correspondence is obtained. As such, method 10 may in some embodiments overcome the limitation of conventional methods in which shorted nets are not accounted for or identified. To provide one non-limiting example, where the functional connectivity template comprises aNAND gate, and where the NAND gate input objects are assigned extemal- net markers, method 10 may be operable to identify an occurrence of the functional connectivity template in the digital object data list even where the existing NAND gate inputs are shorted together.
[0134] In some embodiments, the method 10 may comprise a preliminary step of assigning unique references or annotations to the objects in the netlist and / or template, such as numbers, alphabet letters, alphanumeric characters, or the like, to simplify the recordal of correspondences. In one particular embodiment, assigning unique references may comprise enumerating objects in the netlist and / or template. Notably, such assignment of unique references does not equate to computing labels for objects based on connections or otherwise, but merely provides object identifiers without complex computational labeling.
[0135] In some embodiments, the method 10 is repeated (1) to identify further occurrences of the template in the search space and (2) for a plurality of functional connectivity templates, each defining different digital logic cells. As such, the method 10 may enable identification of different digital logic cells within the netlist and indeed, simplification or compression of the netlist based on the identification of such digital logic cells. In one embodiment, the digital logic cells comprise Boolean logic functions, storage functions or the like. Examples of a digital logic cells may include any one or more of: a transistor (e.g. , metal-oxide semiconductor field-effect transistor (MOSFET) or a bipolar junction transistor), a resistor, a capacitor, or the like.
[0136] In some embodiments, the method 10 may comprise pre-processing the template or plurality of functional connectivity templates. In one embodiment, pre-processing the plurality of functional connectivity templates comprises sorting the plurality of functional connectivity templates in order of decreasing complexity. In another embodiment, pre-processing the plurality of functional connectivity templates comprises sorting the plurality of functional connectivity templates in order of decreasing prevalence.
[0137] In some embodiments, the method 10 may comprises identifying a first template from the (pre-processed) plurality of functional connectivity templates, the first template being the first to be tested against the object data list. As such, it is to be appreciated that where the plurality of functional connectivity templates is sorted in order of decreasing complexity, the method 10 may search for and eventually compresses the digital connectivity representation by identifying occurrences of each functional connectivity template in such order. Where the plurality of functional connectivity templates is sorted in order of decreasing prevalence, the method 10 may search for and eventually compresses the digital connectivity representation by identifying occurrences of each functional connectivity template in such order. If no occurrences of the first template are identified, the method 10 may comprise identifying a second (or subsequent) template from pre-processed plurality of functional connectivity templates, the second (or subsequent) template being the second (or subsequent) to be tested against the object data list.
[0138] In some embodiments, where a search space or netlist has undergone the computer-implemented method in connection with one or all templates, the search space or netlist may be reduced from hundreds or thousands of input components and / or connections, to one or more magnitudes less based on the replacement of templatematching regions with basic template identifiers. In this manner, the input search space or netlist is compressed or compacted, to a relatively smaller search space or netlist which provides useful componentry and / or connectivity information on a large number of components or connections. Put differently, the input search space or netlist may be simplified, such that a simplified object list is produced.
[0139] In some embodiments, validating the correspondence is based on any properties or attributes of the objects tested. For example, the correspondence may be any one of: matched device type, matched name, matched pin name or the like and asthe case may be. In some embodiments, any one or both of the first correspondence and the second correspondence are further validated based on matched connection types.
[0140] In some embodiments, the method may comprise the preliminary step of receiving the search space or netlist. The search space or netlist may be received from an external source or otherwise, may be received from an image-extraction module. In some embodiments, the method may comprise receiving updated templates. In other embodiments, the method may comprise receiving templates in different formats, different hardware description languages or the like.
[0141] In some embodiments, the method may comprise the further step of storing the simplified search space or netlist (or simply, identifiers of templates recognised in the netlist). In some embodiments, the method may comprise the further step of outputting the simplified search space or netlist. The simplified search space or netlist may be outputted to an application programming interface (API) or other user-readable medium.
[0142] In some embodiments, the one or more templates may be stored on a template database, the method utilizing a template recaller to recall a template for testing. Templates may be retrieved in a recall order structured to reduce search complexity. For example, templates may be recalled in order or increasing complexity.
[0143] In some embodiments, the particular existing integrated circuit object is visually identified from the IC or the digital connectivity representation thereof. In this regard, certain a priori knowledge of ICs or the particular IC type under inspection may assist in identifying the particular existing integrated circuit object.
[0144] Several examples are next provided, in order of perceived increasing complexity, to aid in understanding of the methods disclosed herein. In these examples, for the sake of brevity, functional connectivity template(s) are simply referred to as “template(s)” and digital obj ect data list(s) are simply referred to as “netlist(s)”. V arious alternative embodiments and / or additional complementary features are generally excluded in the discussion of these simplified examples.Example 1
[0145] Example 1, which is described with reference to Figure 2, provides a simplified example of implementing the computer-implemented method in accordance with one embodiment of the disclosure. In Figure 2, reference numeral 100 refers to an exemplary template and reference numeral 120 refers to an exemplary netlist (or search space). The template 100 was provided and the input netlist 120 was subsequently received for processing. In this embodiment, each object, being respective nodes (circles) and edges (connecting lines), have been assigned alphabetical identifiers. It is to be appreciated that nodes and edges are used as objects for this illustrative example, but that different objects and / or object types are envisaged in other embodiments, particularly with reference to netlist-based implementations as described herein. As shown, the template 100 and netlist 120 are separate data with no correspondence or relationship recognized between them (although one may appreciate the potential correspondence from a side-by-side visual inspection).
[0146] In this example, the search method comprises assuming a correspondence of a template object of the template 100 with test object in input netlist 120. In particular, the search method assumes a correspondence between object “A” in the template 100 and object “J” in the input netlist 120 (i.e., a starting correspondence or first correspondence), based at least in part on the matched object type between the template 100 and the input netlist 120. In particular, both object “A” and object “J” are nodes (circular) in this simplified example, and the matched object type allows this assumption of correspondence to be made. Therefore, A==J may form the first correspondence assumed by the method. This correspondence may be recorded in a correspondence table in this example (not shown).
[0147] Continuing Example 1, the search method next tests for correspondence between the next or neighbouring objects(s) in both the template 100 and the netlist 120. In particular, the search method identifies that, in the template 100, object “A” is connected to a further object, identified as object “B”. At this point, the object types of “A” and “B” are largely irrelevant, except for the fact that “A” and “B” are connected. The search method then turns to the input netlist 120, to identify whether a further object is connected to “J”. In this example, the search method identifies that a further object is connected to object “J”, identified as object “K”. Once again, the respectiveobject types of “J” and “K” are still largely irrelevant at this point, except for the fact that “J” and “K” are connected. Instead, at this test phase, object “B” of the template 100 is assumed to correspond with object “K” of the input netlist 120. Therefore, B==K may form the second correspondence assumed, which may also be recorded in a correspondence table.
[0148] In this example, the search method next validates the first correspondence recorded based on the second correspondence assumed. In particular, the object types of objects “B” and “K” now become relevant. If the object types of “B” and “K” are indeed matched (i.e., both nodes (circular) or both edges (lines) in this example), the first correspondence A==J is validated. Put differently, the first correspondence A==J is validated since the object types of the second correspondence B==J match. When the first correspondence is validated, it is left unchanged in the correspondence table until such time as the correspondence is rejected. Although not shown here, if the object types of “B” and “K” are not matched (i.e., one is a node (circular) and the other is an edge (line)), the first correspondence A==J is rejected. When the first correspondence is rejected, that correspondence is removed from the correspondence table.
[0149] Continuing Example 1 with reference Figure 2, since the object types of “B” and “K” match, the first correspondence A==J is validated and the step of testing is iterated for further objects in the template 100 and input netlist 120. In this particular, the search method operates in a clockwise direction in the template 100, thus generating the following exemplary correspondence table:A == JB == KC == LD ==ME == NF == P
[0150] Accordingly, in this simplified example, all objects in the template 100 have been found to correspond with and have been validated by objects in the input netlist 120. No conflicts were obtained at any stage. Indeed, it may be said that each of the respective correspondences in the correspondence table was produced and validated, as an identical match between the template objects and the input netlist objects. Notably, the last testing and validating would have occurred between object “F” and object “P” Thereafter, the method would, following the tracing cycle, test object “A” against object “J” once more, however since object “A” was already found to correspond to “J” (i.e., the first item in the correspondence table), and this correspondence is equal to the newly identified correspondence, this equal correspondence is maintained or confirmed (note: each object can only be recorded as a single occurrence in the correspondence table per template run). This aspect of the correspondences is further illustrated with reference to Example 2 below. Thus, in Example 1 and Figure 2, since all of the template objects were found to correspond to objects in the search space, and all of these correspondences were validated, the search space objects can be marked or labelled as part of a template occurrence of template 100, or otherwise replaced entirely with a template identifier representative of the template 100, thereby to simplify or compress the input netlist 120.Example 2
[0151] Example 2, which is described with reference to Figure 3, provides another simplified example of implementing the computer-implemented method in accordance with another embodiment of the disclosure. In Figure 3, reference numeral 100 refers to the same exemplary template of Example 1 (shown in Figure 2) and reference numeral 200 refers to another exemplary netlist (or search space). The template 100 was provided and the input netlist 200 was subsequently received for processing. In this example, the objects of the template 100 still have the alphabetical identifiers assigned thereto in Example 1, and each object, being respective nodes (circles) and edges (connecting lines), of the input netlist 200 have been assigned other alphabetical identifiers. As shown, the template 100 and input netlist 120 are separate data with no correspondence or relationship recognized between them (although one may assume a potential correspondence from a side-by-side visual inspection).
[0152] In this example, similar to the first example, the search method again comprises assuming a correspondence between a template object of the template 100 with an existing object in input netlist 200. In particular, the search method assumes a correspondence between object “A” in the template 100 and object “J” in the input netlist 200, based at least in part on the matched object type between the template 100 and the input netlist 200. In particular, both object “A” and object “J” are nodes (circular), and the matched object type allows this assumption to be made in this example. Therefore, A==J may form the first correspondence assumed in this example. This correspondence may be recorded in a correspondence table, although not shown.
[0153] In this example, again similar to the first example, the search method next tests for correspondence between the next or neighbouring objects(s) in both the template 100 and the input netlist 200. In particular, the search method identifies that, in the template 100, object “A” is connected to a further object, identified as object “B” At this point, the object types of “A” and “B” are largely irrelevant, except for the fact that “A” and “B” are connected. The search method then turns to the input netlist (search space) 200, to identify whether a further object is connected to “J”. In this example, the search method identifies that a further object is connected to object “J”, identified as object “K” Once again, the respective object types of “J” and “K” are still largely irrelevant at this point, except for the fact that “J” and “K” are connected. Instead, at this test phase, object “B” of the template 100 is assumed to correspond with object “K” of the input netlist 200. Therefore, B==K may form the second correspondence assumed. This correspondence may also be recorded in a correspondence table.
[0154] In this example, again similar to the first example, the search method next validates the first correspondence based on the second correspondence assumed. In particular, the object types of objects “B” and “K” now become relevant. If the object types of “B” and “K” are indeed matched (i.e., both nodes (circular) or both edges (lines)), the first correspondence A==J is validated. When the first correspondence is validated, it is left unchanged in the correspondence table until such time as the correspondence is rejected. Although not shown here, if the object types of “B” and “K” are not matched (i.e., one is a node (circular) and the other is an edge (line)), thefirst correspondence A==J is rejected. When the first correspondence is rejected, that correspondence is removed from the correspondence table.
[0155] In this example, since the object types of “B” and “K” match, the first correspondence A==J is validated and the step of testing 20 is iterated for further objects in the template 100 and input netlist 200. The search method continues in a clockwise direction in the template 100, thus generating a correspondence table reflective of correspondence with input netlist 200.
[0156] In this example, therefore, the correspondence table will take the same values as Example 1, up until where the search method attempts to validate F==P. In particular, the search method will eventually test object “F” (a neighbouring template IC object in template 100) against object “P” in the input netlist 200. Since the object types of “F” and “P” are matched, a correspondence will be recorded in the correspondence table.
[0157] To validate this correspondence, the search method will move to the next neighbouring objects in both the template and search spaces. The next neighbouring object of “F” would be object “A” and the next neighbouring object of “P” would be “Q” . Notably, although the object types of “A” and “Q” match, thereby validating the correspondence between objects “F” and “P”, any correspondence between objects “A” and “Q” would be in direct conflict with the correspondence already recorded and validated between objects “A” and “J”. In particular, the correspondence table would be generated as follows (although such table would not be generated, as described below):A == JB == KC == LD == ME == NF == PA == Q
[0158] As shown above, the correspondence table includes two conflicting correspondences for template object “A” in the template 100, being both test object “J” and test object “Q” in the input netlist 200. However, as noted above, each template object in the template 100 must correspond to exactly one test object in the input netlist 200 (i.e., search space). Therefore, in this example, the search method would reject the latest correspondence between objects “A” and “Q” (thus abandoning search path which would have otherwise proceeded from “N” to “Q” through “P”), remove that correspondence and would track or trace backwards to objects “F” and “P” to attempt to find an alternative correspondence which would match the template 100. Since no such alternative correspondence is available in this example, the search method would find that correspondence for “F” cannot be produced in the search space 200, and the correspondence of “F == P” would be removed from the correspondence table, the method thereby tracking or tracing back to the previous correspondence, “E” and “N” to retest for alternative paths, and so forth, until eventually, all correspondences have been removed (including initial assumption “A==J”) and the search result would be that template 100 is not present in input netlist 200.
[0159] It is worth noting that, rejecting the latest correspondence between objects “A” and “Q” results in the abandonment of the search path in the input netlist 200, and therefore correspondences for objects “Q” or “R” are no longer searched for with reference to this particular template 200 unless another correspondence for “A” is located. It is clear from a visual inspection of this simple example that there are no other possible combinations. The search method will thus eventually backtrack back to the first correspondence entry and, discovering there that it cannot produce “A” from “J”.
[0160] In accordance with this example, the search will repeat the steps of assuming, testing and validating, but selecting a new object in the input netlist 200 against which to assume a correspondence for object “A” (this being the starting correspondence assumption). However, based on the logic and procedure of the method described above, it is clear that none of the objects having in the input netlist 200 can correspond successfully to object “A” (i.e., none of “K”, “M”, “P”, or “R” since not the same object type as object “A”, and none of “J”, “L”, “N”, or “Q” since have different connections to the connections of object “A”). Therefore, the template 100 cannot be identified ininput netlist 200 and the search concludes without finding a match or template occurrence.
[0161] As shown with the above Examples, this aspect of the disclosure whereby the search makes correspondence assumptions (in a correspondence table or otherwise) and later either validates that those assumptions still hold true (in which case, the search continues) or discovers an inconsistent assumption (in which case, the search backtracks) allows the search method disclosed herein to operate on graphs containing cycles. This is particularly relevant considering the typical structure of ICs and associated netlists.
[0162] It is to be appreciated that, in most embodiments, since templates typically reflect functional devices, templates will not typically overlap. In this regard, each object will only have a single occurrence in the correspondence table. Indeed, objects already associated with a template (by flagging, marking or replacement, for example), are not typically part of subsequent searching for template occurrences, thereby reducing the number of objects to be searched in subsequent search iterations.Example 3
[0163] Example 3, described with reference to Figure 4, provides another example of implementing the computer-implemented method 10 in accordance with another embodiment of the disclosure. In particular, this embodiment includes applying a permutation rule to objects identified as being permutable (e.g., source and drain pins in MOS devices). In some embodiments, the permutation rule may allow for testing for a template in a search space by reversing two permutable pins and testing for one of the pins (as reversed). If correspondence is identified, the permutation rule may allow for testing of the other pin in the search space.
[0164] In Figure 4, reference numeral 300 refers to an exemplary template and reference numeral 400 refers to an exemplary netlist (or search space). In this embodiment, the template 300 is a PMOS device (p-channel metal-oxide semiconductor transistor) and the input netlist 400 is aNMOS device (n-channel metal- oxide semiconductor transistor), having the respective PMOS and NMOS transistor structure shown.
[0165] Broadly speaking, in this example, the computer-implemented method will attempt to match the PMOS device of the template 300 with one or more PMOS devices in the input netlist 400 (i.e., the search space). In one embodiment, the computer- implemented method may trace or track through the input netlist 400 by commencing with the gate pin (indicated with “Gl”), followed by the channel pins - source (indicated with “SI”) and drain (indicated with “DI”). This methodical tracing or tracking order may be referred to as a “production order” or more specifically, a “pin production order”, and in this embodiment follows an order logical to ICs.
[0166] However, as noted above, the input netlist 400 (or at least, the search space which may be a portion of the input netlist) in this example is in fact a NMOS device, which has source (“S2”) and drain (“D2”) channels / pins reversed as compared to the PMOS device of the template 300. In particular, referring to the lower branches of both devices, the source pin (“SI”) in the template 300 is connected to the Vss supply, whereas in the input netlist search space 400, the drain pin “D2” is connected to the Vss supply. Engineers typically prefer to label the channel pin closest to the supply (e.g., Vss) as the source pin, as shown in the template 300. However, it is to be appreciated that when viewing only the device's layout, such as available in the input netlist 400, the source and drain pins of a MOS transistor are often indistinguishable. In this embodiment, therefore, the source and drain pins are considered permutable by the computer-implemented method.
[0167] In this embodiment, despite the reversed channel pins, the permutation rule may allow the computer-implemented method to still be able to match this template 300 with the search space 400 as follows. As mentioned, the computer-implemented method may begin by testing the gate pin (“Gl”) of the lower portion of the template 300 against the search space 400. The computer-implemented method may determine that both the template 300 and the search space 400 have a net connected to the respective gate pins (“Gl” and “G2”) in the lower portion of each device. As such, at this stage the correspondence table (or at least a portion thereof) may reflect:Gl == G2Input == Input
[0168] Next, the computer-implemented method may search for another gate pin connected to the net in the search space 400, as the template includes another gate pin (“GO”) in the upper portion of the device. The computer-implemented method may assume a correspondence between the template 300 and the search space 400 based on both of the gate pins (“G2” and “G3”) being connected to input nets, and may record this correspondence (relabeled) in the correspondence table. As such, at this stage the correspondence table (or at least a portion thereof) may reflect:G1 == G2Input == InputGO == G3
[0169] Next, the computer-implemented method may test the neighbouring template object, that being the channel pins (source and drain) of the template 300, to find correspondences in the search space 400. In one embodiment, the computer- implemented method may test the source pin (“SI”) of the template 300 and find that it is connected to Vssi supply. During testing against the search space 400, the computer-implemented method may find that the corresponding source pin (“S2”), previously identified, is connected to an output net (in the middle, as shown). As the Vssi net is marked as a supply net and the output net is marked as a signal net, it is clear that these two nets cannot correspond. As such, at this stage the correspondence table (or at least a portion thereof) may reflect the following, until the last entry is removed:G1 == G2Input 0 / 1 == Input 2 / 3GO == G3SI == S2Vssi output 2 / 3
[0170] In an embodiment of the computer-implemented method which does not implement a permutation rule, the computer-implemented method may would “fail” to produce the template 300 in the search space 400 since the objects do not sufficientlycorrespond. The computer-implemented method may therefore back-track to trace or track through the search space 400 using a different path in an attempt to find an exact match or matches to the template 300.
[0171] However, in this example, the computer-implemented method includes implementation of a permutation rule. The permutation rule may comprise different rulesets for different devices and / or objects in different embodiments. In this example, the permutation rule comprises testing for the template PMOS device 300 in the search space 400 and, if that cannot be found, testing for the template PMOS device 300 having the source pin “SI” exchanged for the drain pin “DI”. Put differently, since the computer-implemented method cannot match the PMOS source pin “SI” in the template 300 to the NMOS source pin “S2” in the search space 400, the computer- implemented method implements the permutation rule, and attempts to match the NMOS source pin “SI” in the template 300 to the NMOS drain pin “D2” in the search space 400. This correspondence is assumed and inserted into the correspondence table (as shown below). Since both the source pin “SI” in the template 300 and the drain pin “D2” in the search space 400 are connected to a Vss (Vssi and Vss2, respectively), a supply net, this correspondence is verified. As such, at this stage the correspondence table (or at least a portion thereof) may reflect the following:G1 == G2Input 0 / 1 == Input 2 / 3GO == G3SI == D2Vssl == Vss2
[0172] Given that the computer-implemented method, with the permutation rule implemented, is able to establish a correspondence between the PMOS source pin “SI” in the template 300 and the NMOS drain pin “D2” in the search space 400, the computer-implemented method proceeds by attempting to establish a correspondence between the PMOS drain pin “D2” of the template 300 and the NMOS source pin “S2” of the search space 400. The computer-implemented method will assume acorrespondence between these objects and record it in the correspondence table (as shown below). Since both of these pins (drain pin “DI” in template 300 and source pin “S2” in search space 400) connect to an output net, and no previous correspondence was recorded for these pins (“DI” and “S2”), this correspondence will be successfully verified. As such, at this stage the correspondence table (or at least a portion thereof) may reflect the following:G1 == G2Input 0 / 1 == Input 2 / 3GO == G3SI == D2Vssl == Vss2DI = S2Output 0 / 1 = Output 2 / 3
[0173] Eventually, since this output net connects back to the PMOS devices whose correspondence was previously assumed at the beginning of the computer-implemented method, an exact match will be identified.
[0174] Notably, Figure 4 does not reflect whether transistors are p- or n-type. It is to be appreciated, however, that the template 300 may include p- and n-types (e.g., the S0- G0-D0 transistor being p-type, and the S1-G1-D1 transistor being n-type). In this example, the search space 400 does not include p- and n-types associated with objects since the data is obtained from reverse engineering an IC wherein extraction of p- and n-types may be tedious. As such, the above example further illustrates operation of the method 10 in the absence of p- and n-type data, which is often requisite in conventional IC data processing systems. In other embodiments, the search space can include p- and n-types associated with objects, including when this information is determined from reverse engineering efforts, determined by other input information (including relationships with other objects), or assumed for the purposes of analysis and tagged as such. In some cases, the assumption may eventually be proven correct or incorrect, inwhich case the p-type or n-type association is amended, as well as related downstream or upstream assumptions of such transistor type.
[0175] Although not shown, a further exemplary embodiment of the present disclosure may provide a non-transitory computer readable medium comprising instructions that when executed by a processor, cause the processor to carry out the computer-implemented method described above.
[0176] With reference to Figure 5, in accordance with one embodiment of the method 10, execution thereof allows for tracking or tracing through permuted inverter gate structures in order to identify correspondence. In Figure 5, a circuit diagram of a functional connectivity template 500 is shown on the lefthand side (i.e., the template), representing an inverter, and a circuit diagram of a portion of a netlist 550 is shown on the righthand side (i.e., the search space). In this example, a PMOS tpl in the template 500 cannot match or correspond to the search space 550 because in the template 500, the gate pin of the PMOS tpl is connected to an NMOS tnl whose source is connected to an internal node in the template 500, as shown by the shared tA annotation. In contrast, in the search space 550, the corresponding NMOS snl has a source connected to ground. However, the PMOS tpl in the template 500 does match or correspond to the PMOS sp2 in the search space 550 - the NMOS devices corresponding to the PMOS devices’ respective gates do have their sources connected to ground.
[0177] With reference to Figure 6, the same embodiment of the method 10 allows for tracking or tracing through permuted NAND3 gate structures in order to identify correspondence. In Figure 6, a circuit diagram of a functional connectivity template 600 is shown on the lefthand side, including a NAND3 gate, and a circuit diagram of a portion of a netlist 650 is on the righthand side (i.e., the search space). In this example, the permutation rules or markers described herein aid in working out in the correspondence, particularly with reference to the series MOS configuration. In particular, whilst it may initially appear as if correspondence in the MOS series is between tnl == sn2 and tn2 == snl, reviewing the template 600 reveals that the gate connections on these devices (TA and TB) need to connect to two PMOS devices tpl and tp2 whose source is power and whose drain is the output net. As such, the aforementioned correspondence of between tnl == sn2 and tn2 == snl does not satisfy this condition. However, a correspondence of tp2 == spl and tpl == sp2 does satisfythis condition and therefore an occurrence of the template 600 can be identified in the search space 650 with the implementation of the permutation rule.
[0178] As such, Figures 5 and 6 show that the methods disclosed herein may be operable to find correspondence with templates even against complex combinational logic gates, including groups of devices connected in both series and parallel.
[0179] With reference to Figure 7, in accordance with one embodiment of the method 10, execution thereof allows for backtracking or rewinding of correspondences when a template object is not obtained or validated. This may be relevant when, for example, in an all-or-nothing production rule, the method finds that a second correspondence cannot be obtained. In Figure 7, a circuit diagram of a functional connectivity template 700 is shown on the lefthand side, including two PMOS devices, and a circuit diagram of a portion of a netlist 750 is shown on the righthand side, devoid of a second PMOS device. Consider an implementation wherein the method attempts to find correspondence for the common net from the template 700 in the search space 750. Correspondence is found for a net when all of its pins are produced. In the template 700, the common net has two PMOS devices tpl and tp2. As such, the method will attempt to produce a first PMOS tpl channel connection in the search space 750. Since the search space 750 has a PMOS connected in that configuration (i.e., spl), and the PMOS spl has no other connections, the method will consider there to be correspondence between tpl == spl. According to the template 700, and in accordance with the net production rule, the method must next attempt to find a second PMOS in the search space 750 which corresponds to the template PMOS tp2. Notably, there is no such second PMOS in the search space 750 and as such, the finding correspondence for the common net will fail. In accordance with the backtracking procedure described herein, the method will remove the last recorded correspondence, that being the correspondence for the net only, and returns. This leaves the first PMOS correspondence tpl == spl as recorded, and therefore further backtracking or rewinding is required (described below). Ultimately, however the method will not find an occurrence of the template 700 in the search space 750 in this example, nor will any individual object correspondences be recorded.
[0180] The backtracking or rewinding / reversing procedure can take the form of serval embodiments. In one embodiment, the backtracking procedure involves anincremental parameter which increments as correspondences are recorded. This incremental parameter may be associated with the recorded correspondences, or otherwise may be associated with a field on a netlist object. When the backtracking is to be implemented, and correspondences are to be removed, the backtracking procedure may include checking all template objects and removing all correspondences having a level greater than or equal to the current level. This may be particularly useful when the method searches through recursive connections, as the incremental parameter is essentially indicative of how many stack frames exist in the recursive flow. In another embodiment, the backtracking procedure involves storing correspondences in a separate stack and, if called to remove correspondences of level n and above, for example, will backtrack or rewind the stack pointer to the first correspondence having a level of n. In this embodiment, all correspondences over which the stack pointer moved whilst rewinding are removed.
[0181] Notwithstanding how this backtracking procedure is implemented, it is to be appreciated that such backtracking or rewinding of correspondences may overcome or at least ameliorate the drawbacks of using a direct memory reference technique. Indeed, such a direct memory reference technique would leave previously identified correspondences recorded where correspondences for downstream objects are not obtained or validated and as such, would leave potentially confusing correspondences recorded which may lead to the method failing in subsequent iterations (especially for subsequent templates). Instead, by scrubbing the correspondences of any correspondences which have not been validated, using the backtracking procedure described herein, the method removes any potentially confusing or conflicting correspondences prior to commencing the next search iteration.
[0182] With reference to Figure 8, in accordance with one embodiment of the method 10, execution of the method 10 allows for the recognition of various implementations of the functional connectivity template, particularly where different template implementations are predefined. In Figure 8, the lefthand side shows the functional connectivity template 800, which generally reflects the structure expected for a NAND gate, having two inputs TAI and TB1 and a single output TZ. On the righthand side, two different potential implementations of a NAND gate are shown 820 and 840, as would be present in the digital object data list (either both in a single netlistor in different netlists). For simplicity, these implementations are shown as symbols and do not necessarily reflect each and every component and connection therebetween. In the upper implementation 820, the NAND gate is shown to have two separate inputs, SA and SB, and a single output SZ1. In the lower implementation 840, the NAND gate is shown to have a single input SAB and a single output SZ2. Thus, in this implementation, the two inputs have been shorted. This shorting may be a true shorting on the IC, or may reflect an error in the digital object data list (which, in the case of reverse engineered data, is prone to errors and / or noise). In this embodiment, the template objects TAI and TB1 of the functional connectivity template are marked, for example, with an extemal-net marker (not specifically shown). As such, when the method 10 is executed to test for correspondence between the functional connectivity template 800 and the digital object data list 820 and / or 840, the step of testing would include identifying the extemal-net markers associated with TAI and TB1, and would test for an external net shorted configuration in the digital object data list 820 and / or 840. For the upper implementation 820, the method 10 would identify correspondence between TAI and SA, TB1 and SB, and TZ and SZ1, without encountering any hiccups. For the lower implementation 840, the method 10 would, during testing for correspondence, recognize that TAI and TB1 are marked as external nets. The method 10 would likely identify correspondence between TAI and SAB, but then fail to identify correspondence for TB1. At this point, method 10 may recognize the extemal- net identifier associated with TB1 and may search for a potential other extemal-net to which TB1 may be shorted. After identifying the extemal-net marker associated with TAI, the method 10 may proceed finding correspondence between TAI and TB1 with SAB. The method 10 would then proceed to identify correspondence between TZ and SZ2 such that an occurrence of the functional connectivity template 800 is recognized in the lower implementation.
[0183] Notably, the methods disclosed herein may further include one or more netlist pre-processing steps in different embodiments. Such pre-processing steps may be operable to, for example, partition netlist data for processing with the method, reduce netlist data noise, parallel transistor merging, or the like.
[0184] With reference to Figure 9, and in accordance with a further exemplary embodiment of the instant disclosure, the method 10 may form part of a broader system900 for reverse engineering ICs. In particular, the method 10 in this embodiment is encoded with instructions on a computer-readable medium, which forms a part of the reverse engineering system 900. The instructions may be encoded or otherwise executable as separate modules.
[0185] In this embodiment, the system 900 includes an imaging device 902 for capturing images of an IC (or at least a portion thereof). The imaging device 902 may be any suitable image capturing device, which obtains a resolution sufficient for IC data extraction, including but not limited to SEMs, TEMs, or the like. The imaging device 902 may be coupled to a data store 904, or otherwise captured images may be routed to the data store 904 via another interface. The data store may be any suitable memory, including but not limited to hard-disk and cloud-based memory. The data store 904 may receive and store images captured, as well as any rules or markers inputted by the user.
[0186] The system 900 may further include a digital data processor or similar image processing unit 906 (“processor”) operable to process images in accordance with instructions. In this embodiment, the processor includes the following modules: an image collection module 908 operable to receive and paginate images as required; an image processing module 910 operable to stitch images together and / or manipulate images as required for stitching; a data extraction module 912 operable to extract features of the IC from the images captured and / or stitched so as to provide a raw netlist representative of the features and their layout therein; a compression module 914 operable to receive the raw netlist and apply an embodiment of the method 10 disclosed herein so as to produce a compressed netlist; a reporting module 916 which detects any patterns or noticeable features in the compressed net and an application-programming interface (API) module operable to prepare the data for display. The processor 906 in this embodiment further interfaces with a graphical user interface (GUI), through which data is displayed to the user.
[0187] It is to be appreciated that any one or combination of the extracted raw netlist, the compressed netlist, or the reported netlist may be stored back on the data storage 904 or on a separate memory for later retrieval.
[0188] With reference to Figure 10, and in accordance with a further exemplary embodiment, the present disclosure may extend to a computer program product 1000for reverse engineering ICs (or portions thereof). As shown in Figure 10, the computer program product 1000 in this embodiment comprises a plurality of instructions that, when executed, allow the computer program product 1000 to carry out one or more embodiments of the method 10 disclosed herein. In particular, the computer program product 1000 is operable as an integrated circuit reverse engineering tool. In this embodiment, the computer program product 1000 is operable to receive imaging data 1002 such as, for example, from an imaging device or otherwise from memory; process 1004 the imaging data to extract a netlist representative of the components and connections therebetween; receive 1006 object markers associated with one or more components or connectivity of the netlist, as well as any other a priori data related to the IC or its components or connections; compress 1008 the netlist based on finding exact correspondence with a plurality of functional connectivity templates and taking into consideration the object markers assigned to components or connectivity (as well as any other a priori data received at 1006); output 1010 the compressed netlist in a format readily understandable by users (and optionally including notifications or indicators of patterns or features of the compressed netlist); receive 1012 postcompression input parameters from a user to refine the compressed netlist and / or address any potential template-matching errors noted or requiring input; and update 1014 the compressed netlist in line with post-compression input parameters received.
[0189] It is to be appreciated that the computer program product 1000 may include further instructions which implement further functions or features, and indeed may omit certain instructions, in other embodiments. The computer program product 1000 may indeed be configurable based on the various embodiments disclosed herein. In other embodiments, the computer program product may be operable as an integrated circuit design evaluation tool, wherein the computer program product receives a netlist designed for an IC and the instructions, when executed, carry out the method 10 to identify potential structural errors in the IC design.
[0190] With reference to Figure 11, a circuit diagram of an exemplary inverter is shown. This inverter was utilized in one implementation or run of a computer program product (“program”) implementing the exemplary method disclosed herein, as both the functional connectivity template (having template integrated circuit objects and respectively associated object functional types) and the search space (or the digitalconnectivity representation, having existing integrated circuit objects and respectively associated object functional types), in order to generate a log trace which illustrates the steps of the exemplary method in finer detail. The log trace is reproduced as Figure 12, shown as Figures 12.1 to 12.5, with line numbers and emphasis added for discussion purposes.
[0191] In this implementation, since the same circuit (as shown in Figure 11) was utilized as both the functional connectivity template and the search space, the trace log shown in Figure 12 indicates successful productions when the names of the components are equal. This is for exemplary purposes only, and may be useful when debugging the implementations of the disclosed program. However, it is to be appreciated that the disclosed embodiments (method and / or system and / or program) does not test the names of components for equality (i.e., correspondence is not based on matched naming or labels). As described elsewhere herein, the program (and / or method and / or system) considers only the components, pins and how they are interconnected in order to generate correspondence. It tracks through components and their connections to find correspondences and later validate them based on connectivity, before an occurrence of the functional connectivity template is recognized in the search space.
[0192] Figure 12, lines 2 to 8, illustrates that the program in this implementation commences with recording a first correspondence between a first template integrated circuit object of the functional connectivity template, specifically the template NMOS device (called inv_nl), and a first existing integrated circuit object of the search space, specifically the search space NMOS device (also called inv_nl). This first correspondence is based on an assumption or assumed correspondence to produce a generic instantiated component. In particular, in attempting to produce a correspondence (or “produce_generic_insf ’) between the template NMOS device and the search space NMOS device (both “inv nl”), the program identified that no correspondences had been previously recorded against either the template NMOS device or the search space NMOS device, and therefore since no existing correspondence was found (and indeed, no conflicting correspondence was found), the program assumed a correspondence between these two objects and continued to test neighbouring objects for second and further correspondences. As will be shown, the program will later validate this correspondence based on all neighbouring objects alsohaving (validated) correspondences, thus proving that this initial search assumption was indeed correct. For now, this can be seen from the last two lines of Figure 12 (i.e., “Template obj Inst inv_nl[NMOS] successfully produced from srch obj Inst inv_nl[NMOS]: No more pins. All neighbour pins were produced.”).
[0193] Without going through each step of testing neighbouring existing integrated circuit objects of the search space against neighbouring template integrated circuit objects of the functional connectivity template for correspondence therebetween, with reference to Figures 11 and 12, particularly considering that the skilled artisan would readily understand this iteration from this disclosure, the initial iterations will now be described.
[0194] After correspondence between the template NMOS device and the search space NMOS device (both “inv_nl”) is assumed and recorded, the program will test neighbouring objects or put differently, attempt to produce neighbour objects. It does so by first identifying neighbouring objects in the template (see lines 9 and 10), those being connected to the template “inv_nl”, together with the neighbouring object type, which are specifically Pins D, G and S in this instance, as shown in Figure 11. After identifying and / or retrieving the neighbouring objects (e.g., based on database query or memory lookup), the program will proceed with testing in the tracing operation described elsewhere herein, tracing from the instantiation components to a pin, to a net, and so forth.
[0195] In this example, therefore, the program next tests neighbouring objects identified, specifically pins, for correspondence. As shown at line 11 of the log trace, in this example the program attempts to find a correspondence for “Pin D” as it is connected to “inv nl” in the template, and finds a potential match in the search space (also “Pin D”). The program then reviews whether existing correspondences have been recorded for either the template “Pin D” or the search space “Pin D”. Since in no previous correspondences were recorded for either (see lines 13, 14), there is no conflict, and the template “Pin D” object can be assumed to correspond with the search space “Pin D” object. This correspondence is thus recorded (see lines 16, 17) and the program continues in a depth first manner to test the next neighbouring object.
[0196] Accordingly, the program identifies that the template “Pin D” object is further connected to a net in the template, “inv_ZN” (line 18). The program tests neighbouring objects of search space “Pin D” to find one which corresponds with “inv_ZN”. In this example, the search space “inv_ZN” net is assumed to correspond with the template “inv_ZN”, particularly since no previously recorded correspondences for either were recorded and / or conflicting (lines 19 to 25). The program goes on to attempt to produce correspondence for neighbouring objects in this manner, tracing or tracking through the template and search space, and attempting to produce the template “Pin D” on the “inv_pl” PMOS instantiated component (lines 28 to 36); and then the template “inv_pl” PMOS instantiated component itself (lines 37 to 44).
[0197] After correspondence between the template “inv_pl” PMOS instantiated component and the search space “inv_pl” PMOS instantiated component is assumed and recorded based on no prior correspondence conflict, the program continues in identified connected neighbouring objects, all of which are pins, and attempts to produce template “Pin D” on the “inv_pl” instantiated component (line 47). Recall that the program already assumed correspondence for this object at step 3 and note how the program handles this: the program tests the template “Pin D on inv Pl” against the search space “Pin D on inv Pl” and assumes correspondence, and then identifies that previous correspondences have been recorded for both the template and search objects (lines 50 to 53). However, since the newly assumed correspondence does not conflict with the previous recorded correspondences, and in fact these correspondences are equal, the correspondences are retained (lines 54 to 56). Accordingly, the program recognizes that this Pin D is connected to both instantiated components “inv_ZN” and “inv_pl”, but is in fact a single object with a single correspondence to the template Pin D. Instead of continuing down this path, based on the correspondences being equal, the program returns to the instantiated component “inv_pl” PMOS and continues to search for neighbouring objects (pins), if any, which correspond to connected objects in the functional connectivity template.
[0198] The program thus next finds correspondence for “Pin G” on instantiated component “inv_pl” (lines 58 to 66), and thereafter net “inv_A” (lines 68 to 74), since neither have previously recorded correspondences. When attempting to find correspondence for template “Pin G” on instantiated component “inv_pl” again(tracing back from “inv_A”), the program finds the newly assumed correspondence equal to the previously recorded correspondence at step 5 (lines 77 to 86; to reiterate, based on connectivity, not matched names). Accordingly, this validates the correspondence of “Pin G” on the instantiated component "inv_pl" and therefore this is considered “produced”.
[0199] The program therefore proceeds to next attempt to find correspondence for template “Pin G” on template instantiated component “inv nl”. In this example, as shown in Figure 12, the program first tests template “Pin G” on template instantiated component “inv nl” against search space “Pin G” on instantiated component “inv_pl” (lines 90 to 91). Upon doing so, the program recognizes that whilst no correspondence has been recorded for the template “Pin G” on template instantiated component “inv nl”, correspondence has been previously recorded for search space “Pin G” on instantiated component “inv_pl” at step 5, and therefore this neighbouring search space object does not correspond with the neighbouring template object (lines 96 and 97). Accordingly, the program continues by searching for a different neighbouring object (specifically another Pin G) in the search space against which to test the template “Pin G” on template instantiated component “inv nl”. Since another exists, specifically “Pin G” on the search space “inv_nl”, the program tests this (if no other existed, the program would backtrack here). The program again finds correspondence between the template “Pin G” on instantiated component “inv nl” and the search space “Pin G” on instantiated component “inv nl”, since no previously recorded correspondences conflict therewith (lines 98 to 106).
[0200] Next, following the tracing cycle, the program identifies that the neighboring template object is an instantiated component, specifically template “inv_nl” NMOS (line 107). Recall that the program utilized this instantiated component as the starting point of the program and assumed correspondence for this template object with the search space “inv_nl” at step 0. As shown, program retrieves these previously recorded or existing correspondences (lines 110 to 112), and since they are equal (line 113), the template “inv_nl” NMOS is considered to correspond with and thus be successfully produced from the search space “inv_nl” NMOS (lines 115 to 118).
[0201] Since there are no further pins connected to template net “inv_A” to test, and all neighboring pins were produced, template net “inv_A” is considered by the program to validly correspond to search space net “inv_A” (lines 119 and 120).
[0202] Returning to connections to template instantiated component “inv_pl” PMOS, the program, having already searched and recorded correspondence for “Pin G” on this component, now identifies the next connected pin, template “Pin S” on instantiated component “inv_pl”, and attempts to fiend correspondence between template “Pin S” on instantiated component “inv_pl” and search space “Pin S” on instantiated “inv_pl”. Since there are no previously recorded correspondences which conflict, the new correspondence is recorded (lines 125 to 133).
[0203] As shown in Figure 11 , the neighbouring template obj ect to template “Pin S” on instantiated component “inv_pl” is a net, and specifically template net “VDD! ”. The program proceeds to assume correspondence between the template net “VDD! ” and the search space net “VDD!”, and continues to attempt to produce neighbouring object(s) (lines 134 to 141). At lines 142 and 143, however, the program recognizes that “VDD!” in the template and search space is in fact a power net. Such recognition may be based, for example, on a recursive-object marker assigned the search space net “VDD! ” object based on visual inspection of the IC by an engineer. This recursive-object marker indicates to the program that any downstream objects of the search space net “VDD!” can be assumed to correspond (although not necessarily recorded as such). In particular, identification of this marker being assigned to search space net “VDD!” will lead the program to record a correspondence between template net “VDD!” and search space net “VDD!”, without testing further neighbouring objects of “VDD!” in the search space. This marker is assigned to search space net “VDD! ” based on a priori knowledge that the object is of high complexity, or at least a part of a component of high complexity, which typically requires recursive testing. Indeed, a power net can result in such recursive testing, particularly when multiple components are connected thereto, and this computationally intensive recursive searching would be required to identify template occurrences. Thus, in some embodiments, as described here, power can be treated as a special net (i.e., too may ground nets for practical or timely analysis), and indeed may be treated as a signal pin.
[0204] At lines 144 and 145, the program confirms or verifies that template object “Pin S” on instantiated component “inv_pl” was successfully produced from search space object “Pin S” on instantiated component “inv_pl” as the neighbour net was produced. At lines 146 and 147, the program now moves or traces from the object to the pin, and identifies that the search space pin “Pin S” on instantiated component “inv_pl” produces the template pin “Pin S” on instantiated component inv_pl and therefore, the program continues to the next pin if there is one present. At lines 148 to 149, the program returns that there are no more pins and that since all neighbour pins of the template object were produced in the search space, the template object instantiated component “inv_pl” was successfully produced from search space object instantiated component “inv_pl”.
[0205] At lines 150 and 151, the program confirms or verifies that template object “Pin D” on instantiated component “inv_pl” was successfully produced from search space object “Pin D” on instantiated component “inv_pl” as its neighbour instance was produced. At lines 152 and 153, since template pin “Pin D” on instantiated component “inv_pl” was produced in the search space, the program now moves or traces from that pin to the next pin (if there is one).
[0206] At lines 154 to 162, the program attempts to produce template “Pin D” on instantiated component “inv_nl” in the search space, by testing against search space “Pin D” on instantiated component “inv_pl”. Here, a previously recorded correspondence with reference to the template “Pin D” on instantiated component “inv nl” has been recorded, as well as with reference to the search space “Pin D” on the instantiated component “inv_pl” at step 1. As shown, these correspondences are different, or not equal, and therefore “Pin D” on instantiated component “inv nl” in the search space does not correspond to search space “Pin D” on instantiated component “inv_pl”. Accordingly, the program backtracks by removing or not recording these conflicting correspondences, to test for other potential correspondence. At lines 163 to 170, the program attempting to produce template “Pin D” on instantiated component “inv_nl” in the search space, by testing against search space “Pin D” on instantiated component “inv_nl” is successful, since the previously recorded correspondences for both the template and search space objects are equal and not conflicting. Accordingly, the program is not required to backtrack any further since a correspondence is found.
[0207] At lines 171 and 172, the program confirms that since template pin “Pin D” on instantiated component “inv nl” was produced, the program moves to the next pin (if there is one).
[0208] At lines 173 and 174, the program confirms that since there are no more pins to be tested, and all neighbour pins were produced, the template object net “inv_ZN” was successfully produced from search space object net “inv_ZN”.
[0209] At lines 175 and 176, the program confirms that template object “Pin D” on instantiated component “inv nl” was successfully produced from search space object “Pin D” on instantiated component “inv nl” since the neighbour net was produced.
[0210] At lines 177 and 178, the program identifies that search space pin “Pin D” on instantiated component “inv nl” produces template pin “Pin D” on instantiated component “inv nl”, and therefore the program can move or trace to the next pin (if there is one).
[0211] As shown at lines 179 to 186, the program tests template “Pin G” on the instantiated component “inv nl” against “Pin G” on the instantiated component “inv nl”. Although previously recorded correspondences exist for both the template and search space objects exist, the latter being recorded at step 7, these correspondences are equal and therefore the correspondence between the objects is produced. Since “Pin G” was successfully produced, program tests for the next pin (lines 187 and 188). At lines 189 to 195, the program tests search space “Pin S” on the instantiated component “inv nl” for correspondence to the template “Pin S” on the instantiated component “inv_nl”. Since no previous correspondence has been recorded for either the template object or the search space object, the program records correspondence therebetween and continues to attempt to produce neighbouring objects (if any) in the template.
[0212] At line 196, the program identifies that the template includes a net as a neighbouring obj ect to template “Pin S” on the instantiated component “inv nl ”, which is “VSS!” At lines 197 to 203, the program attempts to find correspondence between the template “VSS!” and an object in the search space, by testing template “VSS!” against search space “VSS!”. The program finds that no existing correspondence have been recorded, and thus records a correspondence between template net “VSS!” and search space net “VSS!”. The program, after recording the correspondence, attempts tofind correspondences for neighbouring object(s) of net “VSS!”, if any in the template. However, at lines 204 and 205, the program recognizes that net “VSS!” in both the template and search space is in fact a ground net. Such recognition may be based, for example, on a recursive-object marker assigned to the search space net “VSS!” object based on visual inspection of the IC by an engineer. This recursive-object marker indicates to the program that any downstream objects of the search space net “VSS!” can be assumed to correspond with objects of the template (although not necessarily recorded as such). In particular, identification of this marker being assigned to search space net “VSS!” will lead the program to record a correspondence between template net “VSS!” and search space net “VSS!”, without testing further neighbouring objects of “VSS ! ” in the search space. This marker is assigned to search space net “VSS ! ” based on a priori knowledge that the object is of high complexity, or at least a part of a component of high complexity, which typically requires recursive testing. Indeed, a ground net can result in such recursive testing, particularly when multiple components are connected thereto, and this computationally intensive recursive searching would be required to identify template occurrences. Thus, in some embodiments, as described here, ground can be treated as a special net (so too may power nets), and indeed may be treated as a signal pin. In other embodiments, the recognition of power / ground may be based on the object type data, available in the netlist, and recognizable by the computer processor during execution of the program. In such embodiments, power and ground do not need to be specifically marked or assigned markers, but may be automatically identified as such special nets, and may cause the program to truncate or halt in-depth searching, to avoid recursive searching and rather assume correspondence therebetween.
[0213] Accordingly, since correspondence was found for net “VSS!”, which neighboured “Pin S” on instantiated component “inv nl”, the correspondence found for “Pin S” on instantiated component “inv_nl” is considered validated (see lines 206 and 207). Similarly, since all template pins neighbouring template instantiated component “inv nl” were produced in the search space, the correspondence between template instantiated component “inv nl” and search space instantiated component “inv_nl” is considered validated (see lines 210 and 211). Accordingly, correspondences recorded are validated based on neighbouring objects corresponding,where such correspondences are tracked in a depth-first manner and where certain markers or object types avoid recursive searching.
[0214] Indeed, in the above example described with reference to Figures 11 and 12, it is noted that the program is operable on the netlist in the absence of connectivity characteristics associated with p- and n-types. Instead, the program focuses on identifying objects and connectivity, based on instantiated components, pins or nets.
[0215] In the example shown in Figures 11 and 12, although not specifically illustrated, it is to be appreciated that since the correspondences recorded reflect validated correspondences between all template objects of the template and all existing objects from the search space, the program includes the further step of marking the existing objects with a template identifier. Accordingly, the program recognizes an occurrence of the template in the search space, and these objects can be regarded as a single template occurrence, thereby simplifying representation thereof and / or processing power required in further uses of the netlist.
[0216] In the example shown in Figures 11 and 12, it is to be appreciated that major backtracking implementations (thought of as backtracking more than one object correspondence) are not required, due to the template and search spaces having identical objects and arrangement. However, such major backtracking implementations may be required when searching for template occurrences in larger search spaces, or indeed when there is no template occurrence in the search space. In this regard, tracking of at which step an object correspondence is recorded may be useful in allowing the program to backtrack to that step when a later conflicting correspondence is recorded, in order to find an alternative object correspondence which may workable.
[0217] The embodiments described above relate generally to reverse engineering of ICs, particularly since IC reverse engineers do not typically have the IC design data, and are more frequently faced with ICs that have been masked or obfuscated in order to, for example, protect from third-parties identification of proprietary functionalities or layouts. As such, the embodiments described herein are generally more tolerable to errors in the netlist data (or other digital object data list), which is typically extracted from images of the IC or based on human-identified components. Indeed, the embodiments described herein allow for inexact template matching, or identification ofa percentage match (e.g., 60% or 90% match), based on structural components of the IC. However, the methods, systems and / or programs disclosed herein are not typically limited to thresholding techniques. Some embodiments allow for the identification of errors, as opposed to merely identifying the general existence of an error.
[0218] Whilst the embodiments described above relate generally to reverse engineering, it is to be appreciated that the same methods, systems and programs may be used equally and / or with alternatives by, for example, an IC manufacturer or buyer as a as an IC design verification system, to verify that the IC as manufactured is in strict compliance with the IC as computationally designed. Otherwise, the methods, systems and programs may be utilized by an IC designer to optimize design of an IC after initial manufacture, or to determine maskable features to avoid reverse engineering by third parties. Indeed, the methods, systems and programs may have several uses wherein examination of an IC or a portion thereof is required to extract design information, and therefore no limitation to reverse engineering is intended.
[0219] While the present disclosure describes various embodiments for illustrative purposes, such description is not intended to be limited to such embodiments. On the contrary, the applicant's teachings described and illustrated herein encompass various alternatives, modifications, and equivalents, without departing from the embodiments, the general scope of which is defined in the appended claims. Except to the extent necessary or inherent in the processes themselves, no particular order to steps or stages of methods or processes described in this disclosure is intended or implied. In many cases the order of process steps may be varied without changing the purpose, effect, or import of the methods described.
[0220] In one pre-processing step, the method may include receiving a bogus net marker associated with or attached to an unconnected pin in the search space which may have an external connection in the template. The bogus net marker may include no other connections. In one embodiment, the bogus net marker may be associated with or attached to any pins in the search space which are not connected to a net. Such preprocessing step may ensure that, for example, when the tracing cycle attempts to produce a net from a pin, the method 10 does not fail due to a lack of net identified in association with the pin, and / or may ensure that a template occurrence is identified despite a net being missing or mislabeled.
[0221] Information as herein shown and described in detail is fully capable of ataining the above-described object of the present disclosure, the presently preferred embodiment of the present disclosure, and is, thus, representative of the subject mater which is broadly contemplated by the present disclosure. The scope of the present disclosure fully encompasses other embodiments which may become apparent to those skilled in the art, and is to be limited, accordingly, by nothing other than the appended claims, wherein any reference to an element being made in the singular is not intended to mean "one and only one" unless explicitly so stated, but rather "one or more." All structural and functional equivalents to the elements of the above-described preferred embodiment and additional embodiments as regarded by those of ordinary skill in the art are intended to be encompassed by the present claims. Moreover, no requirement exists for a system or method to address each and every problem sought to be resolved by the present disclosure, for such to be encompassed by the present claims. Furthermore, no element, component, or method step in the present disclosure is intended to be dedicated to the public regardless of whether the element, component, or method step is explicitly recited in the claims. However, that various changes and modifications in form, material, work-piece, and fabrication material detail may be made, without departing from the spirit and scope of the present disclosure, as set forth in the appended claims, as may be apparent to those of ordinary skill in the art, are also encompassed by the disclosure.
Claims
CLAIMSWhat is claimed is:
1. A computer-implemented method of digitally compressing a digital connectivity representation of at least a portion of an integrated circuit (IC) to be reverse engineered, the computer-implemented method comprising: providing, in accessible computer-readable storage, a functional connectivity template comprising template integrated circuit objects and respectively associated object functional types; receiving, at a digital data processor in data communication with the accessible computer-readable storage, the digital connectivity representation of at least a portion of the IC, the digital connectivity representation comprising digital object list data generated from observational data collected from the IC and comprising existing integrated circuit objects and respectively associated object functional types; recording a first correspondence between a first template integrated circuit object of the functional connectivity template and a first existing integrated circuit object of the digital object list data, wherein the first correspondence is recorded provided it does not conflict with any previously recorded correspondence; testing, by the digital data processor, a neighbouring existing integrated circuit object of the digital object list data against a neighbouring template integrated circuit object of the functional connectivity template for a second correspondence therebetween, wherein if the neighbouring existing integrated circuit object corresponds with the neighbouring template integrated circuit object, the method comprises recording a second correspondence provided it does not conflict with any previously recorded correspondence, and validating the first correspondence recorded; and if the neighbouring existing integrated circuit object does not correspond with the neighbouring template integrated circuit object, the method comprisessearching for a different neighbouring existing integrated circuit object of the digital object list data against which to test the neighbouring template integrated circuit object of the functional connectivity template, and, if none exists, removing the first correspondence.
2. The computer-implemented method of Claim 1, wherein the step of testing is repeated for at least one more neighbouring existing integrated circuit object of the digital object list data.
3. The computer-implemented method of Claim 2, wherein, upon recordal of correspondences between two or more existing integrated circuit objects against all corresponding template integrated circuit objects in the functional connectivity template, the method comprises registering a template occurrence of the functional connectivity template in the digital object list data.
4. The computer-implemented method of Claim 3, wherein registering the template occurrence comprises any one of: flagging the two or more existing integrated circuit objects in the digital object list data with a digital identifier representative of the functional connectivity template; or replacing the two or more existing integrated circuit objects in the digital object list data with a digital representation of the functional connectivity template.
5. The computer-implemented method of Claim 3, wherein upon registration of the template occurrence of the functional connectivity template, the steps of recording and testing are repeated to identify any further occurrences of the functional connectivity template in the digital object list data.
6. The computer-implemented method of Claim 5, wherein the existing integrated circuit objects in the digital object list data registered to correspond with the functional connectivity template are not searched in subsequent steps of recording and testing.
7. The computer-implemented method of Claim 1, wherein any one or both of the first correspondence and the second correspondence comprises at least matching object functional types.
8. The computer-implemented method of Claim 7, wherein if the neighbouring template integrated circuit object is of a permutable object functional type, testing the neighbouring existing integrated circuit object comprises testing the neighbouring existing integrated circuit for permuted correspondence with neighbouring template integrated circuit object.
9. The computer-implemented method of Claim 8, wherein the permutable object functional type is a metal-oxide semiconductor (MOS) channel pin connection which is permutable between a source pin and a drain pin.
10. The computer-implemented method of Claim 1, comprising a step of receiving a recursive-object marker assigned to a given existing integrated circuit object of the digital object list data based on visual inspection of the IC.
11. The computer-implemented method of Claim 10, wherein if the neighbouring existing circuit object is assigned the recursive-object marker, and if the neighbouring existing integrated circuit object corresponds with the neighbouring template integrated circuit object, the method comprises a step of assuming correspondence of any downstream objects of the neighbouring existing integrated circuit object.
12. The computer-implemented method of Claim 11, wherein assuming correspondence of any downstream objects comprises recording a correspondence between the neighbouring existing integrated circuit object and the neighbouring template integrated circuit object, and not testing any objects neighbouring the neighbouring existing integrated circuit object assigned the recursive-object marker.
13. The computer-implemented method of Claim 10, wherein the recursive-object marker is assigned to one or more existing integrated circuit objects known to be of high complexity, or at least a part of an integrated circuit component of high complexity, which typically requires recursive testing.
14. The computer-implemented method of Claim 1, comprising a step of receiving a dispensable-object marker assigned to a given template integrated circuit object of the functional connectivity template.
15. The computer-implemented method of Claim 14, wherein if the neighbouring template integrated circuit object is assigned the dispensable-object marker, and if no neighbouring existing integrated circuit object if found to correspond with the neighbouring template integrated circuit object, a previously recorded correspondence is still validated.
16. The computer-implemented method of Claim 14, wherein the dispensable- object marker is assigned to one or more template integrated circuits objects known to be dispensable without significantly altering functioning of a functional connectivity template or a portion thereof.
17. The computer-implemented method of Claim 1, comprising a step of receiving a net-location marker assigned to one or more template integrated circuit objects of the functional connectivity template, wherein the net-location marker is any one of an internal-net marker and an external-net marker.
18. The computer-implemented method of Claim 17, wherein testing comprises determining if two given template integrated circuit objects each assigned the external- net marker correspond to a single existing integrated circuit object, wherein testing for such correspondence allows shorted nets in the functional connectivity template to be identified.
19. The computer-implemented method of Claim 1, wherein the step of recording a first correspondence comprises assuming the first correspondence, wherein the first correspondence is assumed based on any one of: an existing integrated circuit object having the least number of occurrences in the digital object list data; or an existing integrated circuit object identified as being connected to a predefined component in the digital object list data.
20. The computer-implemented method of Claim 1 , wherein the digital connectivity representation comprises a netlist, and wherein the template integrated circuit objects and the existing integrated circuit objects comprise any one or more of: a pin, a net, or an instantiated component.
21. The computer-implemented method of Claim 20, wherein testing comprises treating any one or both of power and ground as special nets in an initial testing iteration.
22. The computer-implemented method of Claim 21, wherein treating any one or both of power and ground as special nets comprises recognizing any one or both of power and ground as a signal pin.
23. The computer-implemented method of Claim 20, operable on the netlist in the absence of connectivity characteristics associated with p- and n-types.
24. The computer-implemented method of Claim 20, wherein the template integrated circuit objects and the existing integrated circuit objects comprise connectivity characteristics associated with one of a p-type transistor or a n-type transistor.
25. The computer-implemented method of Claim 1, wherein the functional connectivity template defines a digital logic cell, and wherein the steps of recording and testing are repeated for a plurality of functional connectivity templates each defining different digital logic cells.
26. The computer-implemented method of Claim 25, wherein the plurality of functional connectivity templates is sorted in order of any one or both of: decreasing complexity and decreasing prevalence, and wherein the computer-implemented method compresses the digital connectivity representation by identifying occurrences of each functional connectivity template in such order.
27. The computer-implemented method of Claim 1, comprising a preliminary step of deriving at least a part of the digital connectivity representation from one or more images of the IC to be reverse engineered.
28. A computer-implemented method of digitally compressing a digital connectivity representation of at least a portion of an integrated circuit (IC), comprising: providing, in accessible computer-readable storage, a functional connectivity template comprising template integrated circuit objects and respectively associated object functional types; receiving, at a digital data processor in data communication with the accessible computer-readable storage, the digital connectivity representation of at least a portion of the IC, the digital connectivity representation comprising digital object list data comprising existing integrated circuit objects and respectively associated object functional types; searching for correspondences between template integrated circuit objects of the functional connectivity template and existing integrated circuit objects of the digital object list data, wherein correspondences are at least partly based on matched object functional types selected from a net, a pin or an instantiated component; recording correspondences provided each correspondence does not conflict with any previously recorded correspondence; validating, by the digital data processor, each correspondence recorded by testing a neighbouring existing integrated circuit object of the digital object list data against a neighbouring template integrated circuit object of the functional connectivity template for correspondence therebetween; and if the correspondences recorded reflect validated correspondences between all template integrated circuit objects of the functional connectivity template and a selection of existing integrated circuit objects from the digital object list data, marking the selection of existing integrated circuit objects with a template identifier.
29. The computer-implemented method of Claim 28, wherein the steps of searching, recording and validating are repeated to find correspondences in a depth- first manner.
30. The computer-implemented method of Claim 28, wherein if a given neighbouring existing integrated circuit object does not correspond with a givenneighbouring template integrated circuit object, the method comprises searching for a different neighbouring existing integrated circuit object against which to test the given neighbouring template integrated circuit object, and, if none exists, removing a previously recorded correspondence.
31. A non-transitory computer readable medium comprising instructions that when executed by a processor, cause the processor to carry out the computer-implemented method of Claim 1 or Claim 28.
Citation Information
Patent Citations
Approachfor logic signal grouping and RTL generation using XML
US20160292330A1
Behavioral design recovery from flattened netlist
US20200387654A1
Method of recovering a gate-level netlist from a transistor-level
US6190433B1