Formal Equivalence Verification for Processor RTL and Transaction-Level Models
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current processor verification methods, particularly simulation-based approaches, fail to detect all functional bugs due to limitations in stimulating all possible input scenarios and are prone to human error, leading to undetected or overlooked bugs, which can result in delayed product launches and increased costs.
Innovation Solution
A formal verification method that requires only the architecture description, protocol information, and correspondence information, allowing for high-quality verification with reduced user input, and enabling verification in parallel with the design process, ensuring complete coverage of processor functionality including control and data paths.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If simulation-based verification is used, then verification can be performed with existing tools and methods, but functional bugs remain undetected due to insufficient stimulus coverage and human error
Solution Approach 1:
The patent replaces manual simulation-based verification with automated formal equivalence checking. The formal verification system automatically generates test cases and compares RTL implementation against transaction-level specification without human intervention, eliminating the need for manual stimulus creation and bug checking that characterize simulation-based approaches.
Solution Approach 2:
The formal equivalence checking system performs self-verification by automatically generating comprehensive test stimuli and comparing behavioral equivalence between specification and implementation. The system serves itself by autonomously identifying discrepancies without requiring external verification engineers to manually design test cases or interpret results.
2Reliability
If formal equivalence verification is applied to already designed implementations, then verification quality improves, but the verification process occurs too late in the development cycle
Solution Approach 1:
The patent enables formal equivalence verification to be performed in parallel with the RTL design development process. By integrating equivalence checking early and continuously throughout development rather than as a final step, bugs are detected and corrected before the design is complete, preventing launch delays while maintaining high verification quality.
3Reliability
If comprehensive stimulus coverage is achieved through simulation, then all functional bugs can be detected, but the verification time becomes prohibitively long
Solution Approach 1:
The patent replaces time-consuming simulation-based verification with efficient formal equivalence checking. The formal method mathematically proves behavioral equivalence between specification and implementation without requiring exhaustive simulation of all possible input scenarios, achieving complete coverage instantly rather than requiring millions of simulation cycles.
4Reliability
If manual verification planning is performed to identify overlooked bugs, then verification coverage improves, but human error increases the likelihood of missed bugs
Solution Approach 1:
The formal equivalence checking system autonomously identifies all functional discrepancies between specification and implementation without requiring manual verification planning. The automated system systematically compares all behavioral aspects, eliminating the need for human engineers to manually identify and check for overlooked bugs, thereby achieving complete coverage while removing human error entirely.
Data Source
AI summary
A method for formally verifying the equivalence of an architecture description with an implementation description. The method comprises the steps of reading an implementation description, reading an architecture description, demonstrating that during execution of a same program with same initial values an architecture sequence of data transfers described by the architecture description is mappable to an implementation sequence of data transfers implemented by the implementation description, such that the mapping is bijective and ensures that the temporal order of the architecture sequence of data transfers corresponds to the temporal order of the implementation sequence of data transfers, and outputting a result of the verification of the equivalence of the architecture description with the implementation description.


