Security

Security HRoT

Rigorous

Rigorous, high-coverage semi-formal security verification without the capacity limits of formal

Fast

Fast, simplified test generation without the need to learn complex languages or assertions

Portable

Shareable test content across the entire verification process and platforms

Security Verification Background

Ensuring the security of sensitive information or control access has become important for many modern electronic devices. Examples include tamper-proofing an automotive or other safety critical chip or firewalling unencrypted keys in a financial application device. There are many types of potential vulnerabilities in an integrated circuit, but a significant degree of protection can be realized by creating protected, secure regions in hardware or software on a System-on-Chip (SoC). The Breker Security SystemVIP automatically verifies the behavior of these protected regions.

Considering the software and hardware stack on a classic SoC, the most sensitive aspect is the underlying hardware, as once access is gained at this foundational level, it is relatively easy to hack into the software and application layers above. As such, security protection must start with the hardware, leading to the notion of the Hardware Root of Trust (HRoT).

The HRoT can consist of a number of hardware protocols and mechanisms, a common one of which is defining access rules to specific peripherals and memory regions on the device. This may be accomplished using a specific device connected into the SoC fabric or the fabric itself utilizing gateways to control access.

SoC Fabric Security Protocol

SoC Fabric Security Protocol Described Using Tables and an IP-XACT Description

Verifying that the security rules are correctly adhered to and that no other hidden vulnerabilities exist is a complex issue. This form of “negative” verification, where testing is focused on an item of functionality not being present as supposed to functional correctness, is notoriously complex as all of the potential vulnerabilities must be predicted manually.

Formal Verification tools have the advantage that they can automatically derive and inspect the entire state space of the design to see if there are unexpected vulnerabilities. While this is effective for security verification on small blocks, these tools have severe capacity limitations, making them hopelessly inadequate for SoC-level analysis or even large blocks.

The Breker Security SystemVIP

The Breker Security SystemVIP is designed to take the various input mechanisms for each stage of the security protocol in a secure fabric and combine them into a single graph that describes the access protocol between multiple masters and slave devices, memory regions, etc. These stages might describe protocol elements for each device or break a single protocol into subsections. The stage rules could be described using a combination of Excel spreadsheets, IP-XACT descriptions, C code functions, or Portable Stimulus modules. By using these mechanisms — especially Excel tables — a fast, visual inspection will reveal any table elements not completed, suggesting a security hole. Learning Portable Stimulus or any other language is not required.

The Breker Security SystemVIP combines all of these disparate items of information into a single graph that provides a full description of the access rules for the SoC fabric as a whole. This graph represents the entire search space of the fabric and peripheral access protocols, similarly to the formal verification approach to the problem. However, this has the advantage that test content may be synthesized that can execute on a simulation or emulation environment that does not suffer from capacity issues, thereby providing a “semi-formal” approach to the problem with a rigorous coverage level.

SoC Fabric Security Protocol

SoC Fabric Security Protocol Described Using Tables and an IP-XACT Description

This graph is provided as input to the Test Suite Synthesis tools for test content generation. Constraints are automatically applied that direct the synthesis process to explore all possible access approaches through the various stages, thereby setting up rigorous test content that fully verifies possible vulnerabilities right across the fabric and connected devices.

The Breker Test Suite Synthesis technology makes use of Planning Algorithms to optimize verification coverage. Planning Algorithms used in verification are a subset of Artificial Intelligence (AI) algorithms where, starting from a required verification outcome, they work backwards to find the ideal test stimulus, taking into account coverage optimization. This approach provides test content that has the most chance of finding unusual corner-case scenarios that could be employed during a malicious attack on the device to gain access to sensitive areas.

The test content may be ported to various phases of the verification flow, for use with block or SoC designs on virtual platforms, simulation with UVM, SoC verification on simulation or emulation with C tests and transactions, rapid prototyping systems, and final silicon.

All of the capabilities that are provided with the Breker Trek tools are available for use with the Security SystemVIP. A full range of coverage analysis, debug, and design profiling is available. Furthermore, the security test content may be easily shared with other verification tests to allow its inclusion in broader verification intellectual property.