The NCSC research problem book
Pages
Page 11 of 21
HW2 - How do we know that we can trust our devices?

How do we know that we can trust our devices?
In the cross-cutting problems chapter we ask: How can we build systems we can trust when we can’t trust any of the individual components within them? This problem requires an understanding of what trust we have in the hardware devices in a system, and what the limits of that trust are. With increasingly complex devices, more interconnection and global supply chains, this is becoming harder.
Much of this isn’t specific to hardware, but the application to hardware provides some specific challenges that, if addressed, would help us understand the risk we take when we use a given product.
Strands or sub-problems
-
Mapping the supply chain
As a product manufacturer, I might know who designed the chip I have bought, but what about any third-party design IP used? Has the supplier of that IP also bought in further IP? To place more trust in a device, we need to know the full tree of IP in a device: an IP bill of materials (IPBoM). Equally, with manufacturing, packaging and distribution covering multiple continents, it’s valuable to understand the manufacturing chain. Putting these two elements together leads us to ask: how can we improve transparency in the semiconductor supply chain?
-
Assuring devices
This sub-problem is easy to describe, but incredibly hard to solve. How can I know a device does exactly what it says it does, nothing more and nothing less? Reducing risk in this space needs improvements to scalability in verification and inspection, whether that’s manual, automated or formal. For example, how does a developer measure and demonstrate the verification they have carried out? How can we use inspection or alternative methods to detect post-verification changes? Current state-of-the-art verification and inspection techniques are often expensive, and either not scalable, or they’re invasive and destructive, or both, so there are many routes to improve the situation.
-
Demonstrating trust
As we start to develop our understanding of the supply chain and gain improved assurance, we need mechanisms to demonstrate the trust you can have in a device, which includes understanding the current state of the device. This would include, but also expand on, existing attestation techniques and could also consider mechanisms to automate key generation and enrolment. Availability of information about the levels of verification and assurance a device has, and its IPBoM, will help product developers make informed decisions about what they include in their products.
Why this is important
“It’s not currently feasible to gain confidence that a device you haven’t designed and manufactured yourself doesn’t contain anything malicious, and meets your own standards of testing and verification. This means that a product manufacturer can’t truly trust in the devices they include in their systems. But if we can improve our understanding and demonstrate the security and trust you get from any given device, we can begin to mitigate supply chain risks. This directly feeds into how we build trusted and resilient systems, for both commodity and high-assurance uses.”
Máire O’Neill, Professor of Information Security, Queen’s University Belfast