NSA releases guidance to address threats in ASIC development

On August 25, the National Security Agency (NSA) released two technical reports addressing threats to application specific integrated circuits (ASICs) during the design and manufacturing process. The reports — ASIC Best Practices Threat Catalog and the Application Specific Integrated Circuit (ASIC) Level of Assurance 1 (LoA1) Best Practices — explain the threats against ASICs and recommend mitigations to reduce risk.

The ASIC Best Practices Threat Catalog includes threat descriptions in 18 categories of adversary compromise based on common characteristics and mitigations. These categories include design requirements, information technology (IT) systems, electronic design automation (EDA) software, and third-party intellectual property (3PIP). Read the full ASIC Best Practices Threat Catalog for all the descriptions.

The ASIC Level of Assurance 1 (LoA1) Best Practices is the first of three technical reports focused on the detection and prevention of intentional threats to ASICs. Together, these reports will establish three “Levels of Assurance” for custom microelectronic hardware. NSA developed the reports in collaboration with the Department of War’s Joint Federated Assurance Center Hardware Assurance (JFAC HwA) Laboratories.

The LoA1 report is designed for stakeholders in custom microelectronic hardware and applies to ASIC-based designs where system failure could potentially reduce U.S. Government (USG) capabilities. Created using public use cases and input from JFAC HwA subject matter experts in the areas of ASIC design, hardware security, wafer manufacturing, and supply chain assurance, the LoA1 technical report provides multiple mitigation options, allowing users to tailor the best solutions for their needs.

Source: NSA

IC News delivers the situational awareness you need to get ahead and stay ahead in the IC contracting space. Subscribe today for full access to 10,000+ articles, plus new articles each weekday.