Method, system, and apparatus for security assurance, protection, monitoring and analysis of integrated circuits and electronic systems using machine learning instruments and machine learning analysis
A method and system for analysis of a facility may include providing an emulation host system, generating a pristine circuit model on the emulation host system, inserting a first hardware trojan model, emulating operation of the golden circuit model, and emulating operation of the first hardware trojan model, and determine a set of machine-learning models, detecting the presence of an unknown trojan as a function of the set of machine learning models.
1. A method comprising the steps of:
operating an electronic facility comprising a ML instrument by applying operational vectors, said ML instrument being adapted to store operational data associated with a first functional circuit block;
receiving said operational data from said machine learning instrument, said operational data being further characterized as normal operational data;
developing a normal signature as a function of said normal operational data;
storing said normal signature in a signature database;
inserting a first trojan into said electronic facility at a location selected to produce anomalous behavior;
operating said electronic facility by applying operational vectors and a first trojan trigger;
receiving said operational data from said learning instrument, said operational data being further characterized as infected operational data;
developing an infected signature as a function of said infected operational data;
storing said infected signature in said signature database;
inserting a second trojan into said electronic facility at a location selected to produce anomalous behavior;
operating said electronic facility by applying operational vectors and a second trojan trigger;
receiving said operational data from said learning instrument, said operational data being further characterized as unknown operational data;
detecting anomalous behavior of said unknown operational data;
developing a prediction metric as a function of said unknown operational data, said normal signature, and said infected signature;
storing said prediction metric in a prediction database.
2. The method of claim 1 wherein said normal operational data and the infected operational data are further characterized as comprising at least one of temperature, voltage, power consumption, supply voltage variation, ground voltage variation, and timing degradation.
3. The method of claim 1 wherein said normal operational data is further characterized as comprising XML variables.
4. The method of claim 1 wherein said normal operational data is further characterized as comprising a time tag.
5. The method of claim 1 wherein said normal operational data is further characterized as comprising a location tag.
6. A method comprising the steps of:
operating an electronic facility in an emulator system;
embedding a plurality of ML instruments into said electronic facility to form an instrumented pristine model
collecting normal operational data;
developing a normal signature as a function of said normal operational data;
storing said normal signature in a signature database;
inserting a first trojan into said electronic facility at a location selected to produce anomalous behavior;
operating said electronic facility;
collecting infected operational data;
developing an infected signature as a function of said infected operational data;
storing said infected operational signature in a signature database.
7. The method of claim 6 wherein said normal operational data and the infected operational data are further characterized as comprising at least one of temperature, voltage, power consumption, supply voltage variation, ground voltage variation, and timing degradation.
8. The method of claim 6 wherein said normal operational data is further characterized as comprising XML variables.
9. The method of claim 6 wherein said normal operational data is further characterized as comprising a time tag.
10. The method of claim 6 wherein said normal operational data is further characterized as comprising a location tag.