Boolean Network Analysis for FPGA Trust Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current technologies lack scalable and diverse means to ensure the trustworthiness of hardware logic devices, such as FPGAs and ASICs, due to vulnerabilities introduced by untrusted design tools during the design and verification stages, which can lead to unintended logic or trojan insertions that remain hidden during normal operation and conventional testing.

Innovation Solution

A computing system translates netlists into Boolean networks, assigns criticality values to nodes based on metrics generated from functional testing, rare triggers, and stability analysis, and ranks nodes to identify regions susceptible to vulnerabilities, thereby determining the likelihood of trojan insertions or unintended logic and outputting an indication of the netlist's trustworthiness.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional hardware logic devices are used, then device functionality is achieved, but vulnerabilities and trojan insertions remain undetected due to inordinately large numbers of possible activation mechanisms

Engineering Contradiction:
Improvetrustworthiness of hardware logic deviceVSAvoiddetection of vulnerabilities
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments the hardware logic device into modular components represented as nodes in a graph structure. Each node represents a specific hardware component or logic element, and edges represent connections between components. This segmentation allows the system to analyze individual components and their interactions independently, making vulnerability detection more manageable despite the large number of possible activation mechanisms.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary analysis system that translates hardware netlists into graph representations and applies machine learning models to assess trustworthiness. This intermediary layer processes the complex hardware descriptions and generates vulnerability assessments without requiring direct analysis of all possible activation mechanisms, thereby reducing detection difficulty while maintaining reliability assessment.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If untrusted design tools are used, then design productivity is improved, but trojan insertions are introduced into hardware logic device software

Engineering Contradiction:
Improvedesign productivityVSAvoidtrojan insertion
Core Design Contradiction:
ProductivityVSObject-generated harmful factors

Solution Approach 1:

The patent implements a feedback mechanism where the machine learning model continuously assesses the trustworthiness of design tools and their outputs. The system analyzes graph representations of hardware descriptions and provides feedback signals that indicate potential trojan insertions or vulnerabilities. This feedback loop allows the system to detect harmful factors introduced by untrusted design tools while maintaining high design productivity.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent uses disposable graph representations and machine learning models that can be quickly generated and discarded. Instead of performing exhaustive analysis of all hardware configurations, the system creates simplified graph models from netlists and uses pre-trained machine learning classifiers to assess trustworthiness. This approach allows rapid evaluation of design outputs from untrusted tools without the computational burden of complete verification.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Reliability

If comprehensive vulnerability detection is performed, then trustworthiness assessment is improved, but analysis time and computational resources increase significantly

Engineering Contradiction:
Improvetrustworthiness assessment accuracyVSAvoidanalysis time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent creates a simplified copy of the hardware description in graph form, where nodes represent hardware components and edges represent connections. This graph representation is a condensed version of the original netlist that captures essential structural information while reducing complexity. The machine learning model analyzes this simplified copy to assess trustworthiness, achieving accurate evaluations without the time cost of comprehensive exhaustive analysis of the complete hardware description.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent transforms the hardware description from detailed netlist format into graph theoretical parameters such as node degrees, connectivity patterns, and structural motifs. These parameter transformations convert complex hardware descriptions into simplified mathematical representations that machine learning models can process efficiently. By changing the representation parameters, the system achieves fast and accurate trustworthiness assessment without time-consuming exhaustive analysis.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10409994B1FPGA/ASIC framework and method for requirements-based trust assessment
Publication Date: 2019.09.10 NATIONAL TECHNOLOGY & ENGINEERING SOLUTIONS OF SANDIA LLC
  • US10409994B1 patent drawing
  • US10409994B1 patent drawing
  • US10409994B1 patent drawing

AI summary

Described herein are various technologies for metrics-based assessment and trust verification of netlists for hardware logic devices (e.g., ASICs, FPGAs, etc.). A computing system translates a netlist of a hardware logic device into a Boolean network. The computing system generates and assigns metrics to edges of the Boolean network. The metrics comprise a coverage metric, a rare trigger metric, and an influence metric. Based upon the metrics, the computing system assigns the nodes in the Boolean network criticality values. The computing system determines a likelihood of a vulnerability in the netlist based upon the criticality values. The computing can output an indication as to whether the netlist is trusted based upon the determined likelihood of a vulnerability in the netlist.