Hardware System Validation via Bipartite Netlist Graphlet Clustering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for validating hardware systems are computationally expensive and non-deterministic, making it difficult to detect malicious functions like hardware Trojans due to the complexity and diversity of netlist representations, which requires extensive search patterns and learning phases.
Innovation Solution
A computer-implemented method that uses a bipartite netlist model at register transfer level, creating candidate graphs from reference structures, clustering based on similarity, and determining functional behavior to efficiently and accurately validate hardware systems, focusing on sub-structures and graphlets to reduce complexity and enhance detection accuracy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a generalized netlist model is used to analyze hardware systems, then the applicability is improved, but the diversity of netlist representations increases requiring extensive search patterns
Solution Approach 1:
The patent transforms the netlist model by changing parameters: converting bipartite netlists (with cells and links) into monopartite graphs (with nodes and edges), and further transforming them into graphlets (smaller subgraphs with specific structural properties). This parameter transformation reduces the diversity of representations while maintaining structural equivalence, enabling consistent pattern matching across different hardware system representations.
Solution Approach 2:
The patent segments the hardware system model into hierarchical components: the overall netlist is divided into sub-structures, which are further segmented into graphlets (smaller structural units). This segmentation allows the validation process to focus on specific structural patterns rather than analyzing the entire complex netlist, reducing the number of search patterns needed while maintaining detection accuracy.
2Measurement precision
If extensive search patterns are defined to cover all variations of malicious functions, then the detection accuracy is improved, but the computational expense increases
Solution Approach 1:
The patent changes the structural parameters of the search patterns by using graphlets with specific, limited structural configurations instead of extensive varied patterns. The graphlet transformation creates a standardized set of structural templates that can match multiple variations of malicious functions through structural equivalence, reducing the number of patterns needed while maintaining detection accuracy.
Solution Approach 2:
The patent creates universal graphlet structures that can serve multiple detection purposes. Each graphlet structure is designed to be structurally equivalent across different netlist representations, allowing a single graphlet pattern to detect multiple variations of malicious functions that would otherwise require separate search patterns, thereby reducing computational expense while maintaining comprehensive detection.
3Adaptability or versatility
If a probabilistic neural network is used to classify potentially malicious sub-graphs, then the classification capability is improved, but the determinism is lost making it non-applicable to security-relevant validations
Solution Approach 1:
The patent replaces the probabilistic neural network classification mechanism with a deterministic structural equivalence matching mechanism. Instead of using probabilistic learning-based classification, the patent uses exact structural matching between graphlets and reference malicious structures, providing deterministic results that are suitable for security-critical applications while maintaining effective classification capability through structural pattern recognition.
Data Source
AI summary
Disclosed is a method for validating a hardware system by a model thereof, which method comprises: providing reference structures and determining, in the model, sub-structures, each of which is structurally equivalent to one of the reference structures; extracting, from the model, input cones for each sub-structure; creating monopartite candidate graphs by mapping the bipartite sub-structure and the respective input cones to one of the candidate graphs; creating, for each candidate graph, a match vector, each dimension of the match vector comprising a count of occurrences, in the candidate graph, of a different one of predetermined graphlets; clustering, on the basis of similarity of the match vectors, the candidate graphs in clusters; and selecting, from each of the clusters, one candidate graph and determining a functional behaviour of the respective sub-structure of the selected candidate graph for validating the hardware system.


