Static IC Security Verification for Clock, Reset, and Data Paths
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing integrated circuit designs are vulnerable to hardware security threats such as side channel, laser, and trojan attacks, which are difficult to detect and mitigate during the design phase due to the lack of effective static verification methods.
Innovation Solution
Performing hardware security checks during static verification of integrated circuit designs using automated analysis to identify and report potential vulnerabilities, particularly in clock, reset, and data paths, and generating security scores for sub-circuits.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If full simulation is performed to verify integrated circuit design, then verification completeness is improved, but time consumption and computational cost increase significantly
Solution Approach 1:
The patent extracts security verification from the complete simulation process by identifying and analyzing specific security-critical paths (clock paths, reset paths, data paths) separately. This allows security verification to be performed without executing the full simulation, thus reducing time consumption while maintaining verification completeness for security aspects.
Solution Approach 2:
The verification process is segmented into different types of path analysis (clock paths, reset paths, data paths) with specific security checks for each. This segmentation enables targeted verification of security-critical components without requiring complete simulation of the entire circuit, thereby reducing computational time while maintaining thorough security verification.
2Productivity
If static verification is performed to reduce time consumption, then speed is improved, but detection precision of security vulnerabilities decreases
Solution Approach 1:
The patent applies local quality by performing enhanced security-specific analysis on particular paths (clock, reset, data) that are most susceptible to vulnerabilities. Instead of applying the same verification depth throughout the entire circuit, the method concentrates detailed security checking on critical paths while using lighter verification on non-critical paths, thus maintaining high detection precision for security issues while keeping overall verification speed high.
Solution Approach 2:
The patent performs preliminary identification and classification of paths as security-critical or non-critical before executing verification. By pre-analyzing the circuit structure to identify clock paths, reset paths, and data paths, the system can apply appropriate verification depth in advance, ensuring that security vulnerabilities are detected with high precision without requiring exhaustive simulation of the entire circuit.
3Reliability
If security checks are added to static verification process, then security reliability is improved, but device complexity increases
Solution Approach 1:
The patent implements a universal verification framework that handles multiple security verification tasks (clock path security, reset path security, data path security) within a single integrated process. The same verification infrastructure and analysis mechanisms are reused across different path types, which improves hardware security reliability without proportionally increasing device complexity, as the multi-functional approach eliminates the need for separate dedicated verification systems for each security aspect.
Data Source
AI summary
A method includes: receiving an integrated circuit design; classifying, by the processing device, a signal path of a sub-circuit of the integrated circuit design based on a connection between an input port of the signal path and a component of the sub-circuit to generate a classification of the signal path; computing, by the processing device, a security vulnerability result of the sub-circuit of the integrated circuit design based on the classification of the signal path and based on a trust level of a zone in a fan-in cone to an input port of the signal path; and generating a security vulnerability report based on the security vulnerability result of the sub-circuit of the integrated circuit design.


