Hardware Trojan Detection via Information Flow Security Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The detection of hardware Trojans in third-party intellectual property (IP) cores for system-on-chips (SoCs) is challenging due to the lack of a trusted reference version, making it difficult to identify malicious components that can compromise security and integrity, as existing detection techniques can be bypassed by stealthy Trojan designs.
Innovation Solution
The proposed solution employs an information flow security (IFS) verification framework that models assets as faults and uses automatic test pattern generation (ATPG) algorithms to detect violations of confidentiality and integrity policies, identifying observation and control points through which assets can be leaked or influenced, thereby detecting Trojans.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If third-party IP cores are used to reduce R&D cost and speed up development, then productivity and cost efficiency are improved, but security and reliability deteriorate due to potential hardware Trojan insertion
Solution Approach 1:
The patent applies preliminary action by performing information flow tracking and security verification on third-party IP cores before they are integrated into the final SoC design. The verification process identifies potential Trojan insertion points and unauthorized information flows in advance, allowing security issues to be detected and resolved during the IP core validation phase rather than after integration, thus maintaining both high productivity and security
Solution Approach 2:
The patent introduces an intermediary verification framework that acts as a mediator between the third-party IP core vendor and the SoC integrator. This framework includes automated tools that track information flows and verify security properties, serving as an intermediate layer that assesses and certifies the security of IP cores before they are adopted, thereby enabling trusted use of third-party components without sacrificing security
2Difficulty of detecting and measuring
If structural analysis techniques are used to identify suspicious signals, then ease of detection is improved, but detection precision deteriorates because Trojans can be designed to defeat these techniques
Solution Approach 1:
The patent replaces traditional structural analysis methods with a formal verification approach based on information flow tracking. Instead of relying on heuristic metrics like signal activation probability, the system uses automated formal methods to mathematically verify security properties and detect unauthorized information flows, thereby achieving both ease of detection through automation and high precision through formal verification
Solution Approach 2:
The patent changes the detection parameters from structural metrics (such as signal activation probability and circuit complexity) to functional security properties (such as information flow paths and confidentiality violations). This parameter transformation enables the detection system to identify Trojans based on their functional behavior rather than their structural characteristics, making it ineffective for Trojans designed to evade structural analysis
3Ease of operation
If functional simulation is used to identify suspicious regions, then ease of operation is improved, but reliability deteriorates as Trojans can bypass these detection techniques
Solution Approach 1:
The patent replaces functional simulation with formal verification methods. Instead of relying on simulation-based heuristic analysis that can be bypassed by cleverly designed Trojans, the system uses automated formal verification to mathematically prove or disprove security properties. This substitution maintains operational simplicity through automation while dramatically improving reliability by eliminating the limitations of simulation-based approaches
4Measurement precision
If formal verification methods are used to detect Trojans, then detection precision is improved, but device complexity increases due to the need for trusted reference versions
Solution Approach 1:
The patent extracts and focuses verification efforts on specific security-critical information flows rather than attempting to verify the entire IP core. By identifying and isolating the relevant information flow paths that could potentially be compromised by Trojans, the system achieves high detection precision while reducing verification complexity to manageable levels through targeted analysis
Data Source
AI summary
Disclosed are various embodiments for detecting hardware Trojans through information flow security verification. A file comprising register transfer level (HDL) code for an intellectual property core is loaded from memory. An asset within the intellectual property core is identified. An integrity verification or confidentiality verification of the HDL code that represents the asset is performed. An integrity violation or confidentiality violation within the HDL code as a result of performance of the integrity verification or confidentiality violation on the HDL code that represents the asset is detected. A malicious control point or a malicious observation point linked to the asset is identified. Finally, a trigger circuit for a hardware Trojan is identified in response to identification of the malicious control point or malicious observation point.


