Formal Property Verification Assumption Simplification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The complexity of formal verification in electronic design automation is exacerbated by large and complex sets of assumptions, making it computationally impractical to prove or falsify assertions in circuits, as formal property verification is a PSPACE-hard problem.

Innovation Solution

The system automatically approximates assumptions to reduce complexity, allowing for a simplified set of assumptions that are logically equivalent to the original, which can be under- or over-approximated to facilitate formal verification, preserving assertion falsification or proof validity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the full set of assumptions is used for formal verification, then the verification is complete and accurate, but the computational complexity becomes impractical

Engineering Contradiction:
Improveverification accuracyVSAvoidcomputational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the full set of assumptions into multiple subsets, where each subset is associated with a specific assertion. This allows the verification process to only consider relevant assumption subsets for each assertion rather than processing the entire assumption set, thereby reducing computational complexity while maintaining verification completeness.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial action by using approximation techniques that provide either under-approximations or over-approximations of assumption subsets. Under-approximations guarantee assertion falsification preservation, while over-approximations guarantee assertion proof preservation, enabling efficient verification without requiring complete assumption analysis.

Inventive Principle:
Principle #16Partial or excessive action

2Productivity

If the set of assumptions is simplified, then the computational burden is reduced, but the logical equivalence to the original assumptions may be lost

Engineering Contradiction:
Improveverification efficiencyVSAvoidlogical equivalence
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent uses approximation techniques that deliberately provide partial representations of assumption subsets. Under-approximations restrict input assignments to guarantee falsification preservation, while over-approximations expand input assignments to guarantee proof preservation. This partial action approach maintains the necessary logical relationships for verification correctness while reducing computational complexity.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent transforms the original assumptions by changing their parameters through approximation. The system modifies assumption parameters to create simplified versions that either under-approximate or over-approximate the original assumptions, enabling efficient verification while preserving the essential logical properties needed for correct verification results.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8813007B2Automatic approximation of assumptions for formal property verification
Publication Date: 2014.08.19 SYNOPSYS INC
  • US8813007B2 patent drawing
  • US8813007B2 patent drawing
  • US8813007B2 patent drawing

AI summary

One embodiment provides a system, comprising methods and apparatuses, for simplifying a set of assumptions for a circuit design, and for verifying the circuit design by determining whether the circuit design satisfies a set of assertions when the simplified set of assumptions is satisfied. During operation, the system can simplify the set of assumptions by identifying, for an assertion in the set of assertions, a first subset of assumptions which, either directly or indirectly, shares logic with the assertion. Furthermore, the system can modify the first subset of assumptions to obtain a second subset of assumptions which either over-approximates or under-approximates the first subset of assumptions. Then, the system can refine the second subset of assumptions to either prove or falsify the assertion.