Hardware Design Security Vulnerability Detection System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Hardware design transformations often introduce security vulnerabilities that are difficult to detect, especially in sophisticated modern electronic devices, as functional equivalence does not guarantee security equivalence, and defining security vulnerabilities is an unsolvable problem due to varying design-specific concerns.

Innovation Solution

A system that automatically identifies security vulnerabilities by analyzing differences between initial and modified hardware designs using a security model, which represents properties and relationships in the design, and performs simulations or analyses to verify compliance with security constraints, generating notifications or rejecting designs with introduced vulnerabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If hardware design transformations are applied to optimize functionality, then device performance and efficiency are improved, but security vulnerabilities are introduced

Engineering Contradiction:
Improvedevice performanceVSAvoidsecurity vulnerability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs security analysis on the modified hardware design before deployment, comparing it against the original design to detect vulnerabilities introduced by transformations. This preliminary detection allows security issues to be identified and addressed before the transformed design is implemented, preventing vulnerable designs from reaching production.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If manual inspection methods are used to detect security vulnerabilities, then detection accuracy can be maintained, but the process becomes impractical for sophisticated modern designs

Engineering Contradiction:
Improvedetection accuracyVSAvoiddesign complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system introduces an automated intermediary tool that bridges the gap between manual inspection accuracy and automated analysis scalability. This tool uses formal verification techniques and comparison algorithms to automatically detect security vulnerabilities with high accuracy, making security analysis feasible even for extremely sophisticated modern designs without requiring manual inspection.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If functional equivalence is achieved through design transformations, then device functionality is preserved, but security equivalence is not guaranteed

Engineering Contradiction:
Improvefunctional equivalenceVSAvoidsecurity equivalence
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system implements a feedback mechanism that compares the original hardware design with the modified design to detect security vulnerabilities. By analyzing differences between the two designs and evaluating them against security criteria, the system provides feedback on whether security equivalence has been maintained, allowing developers to identify and correct security issues while preserving functional equivalence.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11921907B2Detecting security vulnerabilities introduced between versions of a hardware design
Publication Date: 2024.03.05 ARTERIS INC
  • US11921907B2 patent drawing
  • US11921907B2 patent drawing
  • US11921907B2 patent drawing

AI summary

Methods, systems, and apparatus, including computer programs encoded on computer storage media, for identifying security vulnerabilities introduced by transformations to a hardware design. One of the methods includes obtaining a security model for an initial electronic hardware design and a modified electronic hardware design. An analysis process is performed on the initial representation and on the modified representation of the electronic hardware design according to the security model. If the modified electronic hardware design introduced a security vulnerability relative to the initial electronic hardware design, information representing the introduced security vulnerability is provided.