Automated fault injection testing
Inventors
Fletcher, Austin • SU, Daniel • Boccuzzi, Bradley
Assignees
Interested in licensing this patent?
MTEC can help explore whether this patent might be available for licensing for your application.
Abstract
An automated fault injection testing and analysis approach drives fault injection into a processor driven instruction sequence to quantify and define susceptibility to external fault injections for manipulating instruction execution and control flow of a set of computer instructions. A fault injection such as a voltage or electromagnetic pulse directed at predetermined locations on a processor (Central Processing Unit, or CPU) alters a result of a processor instruction to change values or execution paths. One or more quantified injections define an injection chain that causes a predictable or repeatable deviant result from an expected execution path through the code executed by the processor. Based on accumulation of fault injections and results, a repeatable injection chain and probability identifies an external action taken on a processing device to cause unexpected results that differ from an expected execution of a program or set of computer instructions.
Core Innovation
The invention is a testing device configured to force a control flow of an instruction sequence by receiving an instruction sequence of machine instructions under analysis, storing the instruction sequence in a memory adapted for execution by a processor, and using a code disassembler to identify a candidate instruction in the instruction sequence stored in the memory. A debugging utility identifies a memory location storing the candidate instruction and estimates a duration for execution to proceed to the memory location storing the candidate instruction.
An EMF inducer performs a sample injection from an external disruptive occurrence directed to modifying a result of the candidate instruction stored in the memory location at an execution time based on the estimated duration. The invention further provides results evaluation based on an execution path taken as a result of the sample injection, and a results analyzer evaluates a path result based on the execution path.
Iterative repetition is used for dynamically analyzing a sample injection directed to modify the candidate instruction, and the results analyzer gathers and accumulates sample injections leading to the modified result during iterative repetitions. A logic analyzer estimates the duration by identifying the instructions included in the execution path and accumulating a time required for aggregate processing of each of the instructions on the execution path prior to the candidate instruction.
The testing device also can generate an injection instruction sequence stored in a non-executed memory region allocated to the instruction sequence, and direct a breakpoint at an identified preceding instruction so that the injected instruction sequence executes when program execution attains the identified preceding instruction.
Claims Coverage
The independent claims include three related devices/program implementations and describe at least six core inventive features.
Control flow forcing for an instruction sequence with EMF injection timed by estimated execution duration
Receiving and storing an instruction sequence, identifying a candidate instruction via a code disassembler, using a debugging utility to identify a memory location storing the candidate instruction and estimate a duration for execution to proceed to that memory location, and performing a sample injection from an external disruptive occurrence using an EMF inducer to modify a result of the candidate instruction at an execution time based on the estimated duration.
Iterative dynamic analysis with path result evaluation
Iteratively repeating sample injections for dynamically analyzing a sample injection directed to modify the candidate instruction, with a results analyzer evaluating a path result based on an execution path taken as a result of the sample injection and gathering and accumulating sample injections leading to the modified result during the iterative repetitions.
Execution-path timing aggregation with a logic analyzer
Estimating the duration by identifying the instructions included in the execution path and accumulating a time required for aggregate processing of each of the instructions on the execution path prior to the candidate instruction.
Injection instruction sequence stored in a non-executed memory region and breakpoint-directed execution
Identifying an instruction preceding the candidate instruction, generating an injection instruction sequence for generating the sample injection, identifying a non-executed memory region in a program memory space allocated to the instruction sequence with sufficient space for storing the injection instruction sequence, storing the injection instruction sequence in the identified non-executed memory region, and directing a breakpoint at the identified preceding instruction for executing the injected instruction sequence upon program execution attaining the identified preceding instruction.
Computer program embodying candidate-instruction identification and path evaluation
A computer program on a non-transitory computer readable storage medium that performs steps for identifying a candidate instruction, determining a memory location storing the candidate instruction, estimating a duration for execution to proceed to the memory location, performing a sample injection from an external disruptive occurrence directed to modifying a result of the candidate instruction, and evaluating a path result based on an execution path taken as a result of the sample injection.
The claim coverage centers on forcing control flow of an instruction sequence by disassembling to identify a candidate instruction, determining the candidate instruction memory location and execution duration, timing an EMF sample injection from an external disruptive occurrence to modify the candidate instruction result, and analyzing the resulting execution path and path result with iterative repetition, branch/probability-based accumulation, and optional breakpoint-directed execution from a non-executed memory region.
Stated Advantages
Not explicitly described in patent.
Documented Applications
Not explicitly described in patent.
Interested in licensing this patent?