Logic Circuit Security Analysis via Virtual Model Simulation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing complexity of logic circuits makes it difficult to comprehensively investigate the impact of possible attacks on functionality and security, requiring more efficient methods for security analysis and optimization during the design phase.

Innovation Solution

A computer-aided method that expands the circuit model with safety analysis mechanisms, assigning defined safety properties to components and channels, simulating attacks to generate security risk reports, and adjusting security measures based on vulnerability assessments and attack graphs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If comprehensive security analysis methods are applied to investigate the impact of attacks on logic circuits, then security assessment reliability is improved, but analysis time and computational resources increase

Engineering Contradiction:
Improvesecurity assessment reliabilityVSAvoidanalysis time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by performing security analysis during the design phase using virtual circuit models before actual hardware is built. Security properties are assigned to components and channels in the virtual model, and attacks are simulated in advance to identify vulnerabilities before deployment, thus ensuring reliable security assessment without excessive analysis time during implementation

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying by creating virtual circuit models that replicate the functionality and security properties of actual logic circuits. These models include copies of components, channels, and security mechanisms, allowing comprehensive security analysis to be performed on the copy without affecting the actual circuit, thereby maintaining reliability while reducing analysis time and resource consumption

Inventive Principle:
Principle #26Copying

2Productivity

If security analysis is performed on high-level abstract circuit models, then analysis speed is improved, but detection precision of security vulnerabilities decreases

Engineering Contradiction:
Improveanalysis speedVSAvoidvulnerability detection precision
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent applies local quality by assigning specific security properties to individual components and channels within the virtual circuit model. Different security attributes (confidentiality, integrity, availability) are localized to specific parts of the circuit, allowing the simulation to maintain high analysis speed at the system level while achieving precise vulnerability detection at the component level through targeted security property verification

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent uses dimensionality change by extending the virtual circuit model from purely functional dimensions to include security property dimensions. The model is enriched with additional attributes such as security status, security requirements, and vulnerability metrics, allowing simultaneous achievement of fast analysis through high-level modeling and precise detection through multi-dimensional security property assessment

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If multiple security measures are integrated into circuit design to protect against attacks, then security robustness is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity robustnessVSAvoidcircuit design complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by creating virtual circuit models that serve multiple functions: functional simulation, security property verification, and vulnerability assessment. The same model infrastructure is used to evaluate multiple security measures simultaneously, reducing design complexity by avoiding separate analysis tools while maintaining high security robustness through comprehensive multi-functional evaluation

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses feedback by implementing simulation units that automatically verify security properties and generate feedback information about vulnerabilities and security risks. This automated feedback mechanism helps manage circuit design complexity by providing systematic guidance on security measure effectiveness, allowing designers to iteratively optimize security robustness without being overwhelmed by manual analysis of multiple security measures

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3136268B1Method for analyzing the security of a logic circuit
Publication Date: 2019.06.19 SIEMENS AG
  • EP3136268B1 patent drawingFigure 1~2
  • EP3136268B1 patent drawingFigure 3~5
  • EP3136268B1 patent drawingFigure 6

AI summary

The invention relates to a method for analyzing a logic circuit comprising several components (3, 3', 3", 3'') and channels (5, 5') for exchanging data between components (3, 3', 3", 3''), wherein, for a simulation of the logic circuit's operation, functional properties are assigned to each component (3, 3', 3", 3'') and each channel (5, 5') in a circuit model (1). In a method section, the circuit model (1) is extended by mechanisms for safety analysis such that at least one defined safety property (6) is assigned to each component (3, 3', 3", 3'') and/or each channel (5, 5'), and safety-relevant data (16, 16', 16") is linked to at least one defined safety requirement (8) and to a safety status.Furthermore, in a further procedural step, the following procedural steps are carried out using a simulation unit (9): Checking whether the security property (6) of the respective component (3, 3', 3", 3"') and/or the respective channel (5, 5') corresponds to the security requirement (8) of the security-relevant data (16, 16', 16") and, if not, generating a security risk report; Applying a modeled attack (10, 11, 12, 13) to a component (3, 3', 3", 3"') and/or a channel (5, 5'); Determining a vulnerability of the security property (6) of the respective component (3, 3', 3", 3"') and/or the respective channel (5, 5') by the applied attack (10, 11, 12, 13) and, if a vulnerability of the security property (6) is found Generating an attack report (18).