Automated fault injection testing

Inventors

Fletcher, AustinSU, DanielBoccuzzi, Bradley

Assignees

Two Six Labs LLC

Interested in licensing this patent?

MTEC can help explore whether this patent might be available for licensing for your application.

Publication Number

US-12135635-B1

Patent

Publication Date

2024-11-05

Expiration Date


Abstract

An automated fault injection testing and analysis approach drives fault injection into a processor driven instruction sequence to quantify and define susceptibility to external fault injections for manipulating instruction execution and control flow of a set of computer instructions. A fault injection such as a voltage or electromagnetic pulse directed at predetermined locations on a processor (Central Processing Unit, or CPU) alters a result of a processor instruction to change values or execution paths. One or more quantified injections define an injection chain that causes a predictable or repeatable deviant result from an expected execution path through the code executed by the processor. Based on accumulation of fault injections and results, a repeatable injection chain and probability identifies an external action taken on a processing device to cause unexpected results that differ from an expected execution of a program or set of computer instructions.

Core Innovation

The invention is a testing device configured to force a control flow of an instruction sequence by receiving an instruction sequence of machine instructions under analysis, storing the instruction sequence in a memory adapted for execution by a processor, and using a code disassembler to identify a candidate instruction in the instruction sequence stored in the memory. A debugging utility identifies a memory location storing the candidate instruction and estimates a duration for execution to proceed to the memory location storing the candidate instruction.

An EMF inducer performs a sample injection from an external disruptive occurrence directed to modifying a result of the candidate instruction stored in the memory location at an execution time based on the estimated duration. The invention further provides results evaluation based on an execution path taken as a result of the sample injection, and a results analyzer evaluates a path result based on the execution path.

Iterative repetition is used for dynamically analyzing a sample injection directed to modify the candidate instruction, and the results analyzer gathers and accumulates sample injections leading to the modified result during iterative repetitions. A logic analyzer estimates the duration by identifying the instructions included in the execution path and accumulating a time required for aggregate processing of each of the instructions on the execution path prior to the candidate instruction.

The testing device also can generate an injection instruction sequence stored in a non-executed memory region allocated to the instruction sequence, and direct a breakpoint at an identified preceding instruction so that the injected instruction sequence executes when program execution attains the identified preceding instruction.

Claims Coverage

The independent claims include three related devices/program implementations and describe at least six core inventive features.

Control flow forcing for an instruction sequence with EMF injection timed by estimated execution duration

Receiving and storing an instruction sequence, identifying a candidate instruction via a code disassembler, using a debugging utility to identify a memory location storing the candidate instruction and estimate a duration for execution to proceed to that memory location, and performing a sample injection from an external disruptive occurrence using an EMF inducer to modify a result of the candidate instruction at an execution time based on the estimated duration.

Iterative dynamic analysis with path result evaluation

Iteratively repeating sample injections for dynamically analyzing a sample injection directed to modify the candidate instruction, with a results analyzer evaluating a path result based on an execution path taken as a result of the sample injection and gathering and accumulating sample injections leading to the modified result during the iterative repetitions.

Execution-path timing aggregation with a logic analyzer

Estimating the duration by identifying the instructions included in the execution path and accumulating a time required for aggregate processing of each of the instructions on the execution path prior to the candidate instruction.

Injection instruction sequence stored in a non-executed memory region and breakpoint-directed execution

Identifying an instruction preceding the candidate instruction, generating an injection instruction sequence for generating the sample injection, identifying a non-executed memory region in a program memory space allocated to the instruction sequence with sufficient space for storing the injection instruction sequence, storing the injection instruction sequence in the identified non-executed memory region, and directing a breakpoint at the identified preceding instruction for executing the injected instruction sequence upon program execution attaining the identified preceding instruction.

Computer program embodying candidate-instruction identification and path evaluation

A computer program on a non-transitory computer readable storage medium that performs steps for identifying a candidate instruction, determining a memory location storing the candidate instruction, estimating a duration for execution to proceed to the memory location, performing a sample injection from an external disruptive occurrence directed to modifying a result of the candidate instruction, and evaluating a path result based on an execution path taken as a result of the sample injection.

The claim coverage centers on forcing control flow of an instruction sequence by disassembling to identify a candidate instruction, determining the candidate instruction memory location and execution duration, timing an EMF sample injection from an external disruptive occurrence to modify the candidate instruction result, and analyzing the resulting execution path and path result with iterative repetition, branch/probability-based accumulation, and optional breakpoint-directed execution from a non-executed memory region.

Stated Advantages

Not explicitly described in patent.

Documented Applications

Not explicitly described in patent.

JOIN OUR MAILING LIST

Stay Connected with MTEC

Keep up with active and upcoming solicitations, MTEC news and other valuable information.