Hardware Information Flow Tracking for Pre-Fabrication Vulnerability Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing hardware design analysis methods are inadequate for identifying and mitigating vulnerabilities before fabrication, making devices susceptible to sensitive information leakage or malicious attacks.
Innovation Solution
Implementing information flow tracking in hardware designs to automatically identify and mitigate confidentiality and integrity vulnerabilities by generating modified designs with additional logic elements, simulating input signals, and evaluating flow signals against security criteria to guide design alterations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual inspection methods are used to identify hardware vulnerabilities, then security weaknesses can be detected, but the process is time-consuming and relies on guessing rather than systematic analysis
Solution Approach 1:
The patent replaces manual mechanical inspection processes with an automated computer-based system that uses formal methods and information flow analysis. The system automatically generates security properties, models information flows, and verifies vulnerabilities without human intervention, thereby eliminating the time loss associated with manual guessing and inspection while improving detection reliability through systematic automated analysis.
Solution Approach 2:
The system enables the hardware design itself to be analyzed and verified for vulnerabilities through automated formal methods. The computer system self-service by automatically generating security properties, modeling information flows, and detecting vulnerabilities without requiring external manual inspection, thereby reducing analysis time while maintaining high reliability through rigorous automated verification.
2Reliability
If pre-fabrication manual inspection is performed to identify vulnerabilities, then security issues can be found, but vulnerabilities may not be fixable after fabrication unlike software vulnerabilities
Solution Approach 1:
The patent applies preliminary action by performing automated vulnerability analysis and detection during the design phase, before hardware fabrication. The system generates security properties, models information flows, and identifies vulnerabilities while the design is still modifiable, allowing security issues to be corrected in the design rather than requiring costly post-fabrication fixes or recalls.
Solution Approach 2:
The system provides automated feedback about security vulnerabilities in the hardware design during the design phase. By continuously analyzing information flows and comparing them against security properties, the system delivers immediate feedback on potential vulnerabilities, enabling designers to correct issues before fabrication while the design is still flexible and modifiable.
3Difficulty of detecting and measuring
If conventional guessing-based approaches are used to identify security weaknesses, then some vulnerabilities may be found, but the process lacks systematic methodology and automation
Solution Approach 1:
The patent replaces the mechanical guessing process with an automated computer-based formal analysis system. The system systematically generates security properties, models information flows using formal methods, and automatically detects vulnerabilities through rigorous mathematical verification, eliminating the need for manual guessing while providing high-level automation in the vulnerability detection process.
Solution Approach 2:
The system segments the vulnerability detection process into distinct automated stages: generating security properties from hardware descriptions, modeling information flows through the design, and verifying vulnerabilities against security criteria. This systematic segmentation replaces the unstructured guessing approach with a methodical automated process that can be executed and verified by computers.
Data Source
AI summary
Methods, systems, and apparatus, including computer programs encoded on computer storage media, for performing information flow analysis on hardware designs to identify vulnerabilities. One of the methods includes generating input signals and feeding the generated input signals into the modified hardware design to generate a plurality of information flow signals, wherein the information flow signals each associate a respective input signal with a location in the modified hardware design to which the input signal was able to reach through logic circuitry of the modified hardware design. The generated information flow signals are evaluated according to one or more security criteria to generate security results. One or more security related applications are performed to generate information representing aspects of the design that are vulnerable to insecure behavior.


