The rapid expansion of the RISC-V ecosystem has ushered in a new era of open-standard instruction set architecture (ISA) adoption, but it has simultaneously introduced complex challenges regarding the security of third-party intellectual property (IP). In a landmark collaboration, Cycuity, BAE Systems, and SiFive have introduced a systematic security assurance methodology designed to standardize how hardware vulnerabilities are identified, verified, and mitigated. By leveraging the MITRE Corporation’s Common Weakness Enumeration (CWE) framework, this methodology provides a repeatable blueprint for ensuring that RISC-V cores meet stringent security requirements before they are integrated into larger systems.
As semiconductor designs become increasingly modular, the reliance on third-party IP (3PIP) has grown. However, the lack of transparency in 3PIP often creates a "black box" scenario where the end-user or system integrator cannot fully vet the underlying security posture of the hardware. The methodology developed by these three organizations seeks to eliminate this opacity by introducing reusable assurance templates and portable security tests, effectively streamlining the verification process for the broader RISC-V community.
The Shift Toward Hardware-Centric Security Assurance
For decades, the primary focus of cybersecurity was relegated to the software layer. However, the discovery of hardware-level vulnerabilities such as Spectre and Meltdown in 2018 fundamentally shifted the industry’s perspective. These exploits demonstrated that even if software is perfectly written, flaws in the underlying processor microarchitecture—such as speculative execution or side-channel leakage—can be exploited to extract sensitive data.
In the RISC-V domain, where the open-source nature of the ISA allows for diverse implementations by various vendors, the need for a unified security language is paramount. The methodology presented by Cycuity, BAE Systems, and SiFive addresses this by adopting the CWE framework, which was traditionally used for software but has recently been expanded to include hardware-specific weaknesses. This transition allows hardware designers to categorize vulnerabilities such as improper access control, information leakage through side channels, and insufficient power management protections in a way that is consistent across different implementations.
Technical Framework: Reusable Templates and Golden Models
The core of the new methodology lies in its ability to scale across different processor designs without requiring a complete overhaul of the verification environment. This is achieved through three primary innovations: reusable assurance templates, portable security tests, and the use of a "golden model" as a reference point.
Reusable Assurance Templates
Verification engineers often spend a significant amount of time defining security properties for each new chip design. The methodology mitigates this by providing templates that map specific CWEs to formal verification properties. For example, if a design must be protected against "CWE-1247: Improper Protection Against Voltage and Clock Glitches," the template provides the necessary logic and assertions to test for this weakness automatically. These templates act as a bridge between high-level security requirements and low-level RTL (Register Transfer Level) code.
Portable Security Tests
The collaboration emphasizes the creation of security tests that are not tied to a specific simulation environment. By making these tests portable, they can be utilized throughout the entire lifecycle of the IP—from initial design and simulation to post-silicon validation. This portability ensures that security is not a "one-and-done" checkbox but a continuous process that remains valid as the IP is integrated into different System-on-Chips (SoCs).
The Golden Model Reference
To ensure the accuracy of the verification, the methodology utilizes a "golden model"—a high-level, trusted representation of the processor’s intended behavior. By comparing the actual RTL implementation against this golden model, the methodology can identify discrepancies that might indicate a security vulnerability. This comparative analysis is particularly effective in detecting "trojans" or unintended logic that may have been introduced during the design process.
Case Study: Implementing Assurance on the SiFive X280
To demonstrate the efficacy of the methodology, the partners applied it to the SiFive X280, a high-performance RISC-V processor that features a multi-core capable, 512-bit wide vector unit. The X280 is widely used in applications involving artificial intelligence, machine learning, and high-performance computing, making it a critical target for robust security assurance.
The implementation focused on 60 specific CWEs identified as being in-scope for the X280’s architectural and microarchitectural features. These CWEs covered a broad spectrum of potential vulnerabilities, including:
- Resource Contention: Ensuring that data from one process cannot be inferred by observing the resource usage of another.
- Debug and Test Access: Verifying that debug interfaces do not provide unauthorized access to secure memory regions.
- Privilege Escalation: Confirming that the hardware correctly enforces boundaries between machine, supervisor, and user modes.
The results of the demonstration showed a significant reduction in non-recurring engineering (NRE) effort. By using the standardized CWE-based approach, the team was able to achieve comprehensive coverage of the targeted weaknesses more efficiently than traditional, ad-hoc verification methods.
Chronology of Hardware Security Standardization
The development of this methodology is the result of several years of industry movement toward formalized hardware security.

- 2018: The emergence of Spectre and Meltdown highlights the critical need for hardware-level security verification.
- 2019: MITRE Corporation, in collaboration with industry leaders, begins the formal expansion of the CWE list to include hardware-specific entries (Hardware CWEs).
- 2020-2021: The RISC-V International organization establishes security standing committees to address the unique needs of the open ISA.
- 2022: Cycuity (formerly Tortuga Logic) and BAE Systems begin collaborating on automated security path analysis to detect vulnerabilities in complex RTL.
- 2023-2024: The partnership with SiFive matures, leading to the development of the scalable methodology and its successful application to the X280 core, culminating in the publication of the GOMACTech-24 paper.
Stakeholder Reactions and Industry Implications
The collaboration represents a convergence of interests between three distinct sectors of the semiconductor ecosystem: a security tool provider (Cycuity), a defense and aerospace system integrator (BAE Systems), and a leading IP vendor (SiFive).
From the IP Provider Perspective (SiFive): For SiFive, the methodology provides a way to offer "certified" or "assured" IP to customers who operate in high-stakes environments. As RISC-V competes with proprietary architectures like ARM, the ability to demonstrate a rigorous, standardized security audit becomes a competitive advantage.
From the System Integrator Perspective (BAE Systems): BAE Systems requires high levels of trust for hardware used in defense applications. The ability to verify third-party IP using a repeatable methodology reduces the risk of supply chain vulnerabilities and ensures that the final system meets Department of Defense (DoD) security standards.
From the Security Tooling Perspective (Cycuity): Cycuity’s role in providing the Radix security verification platform is central to the methodology. By automating the analysis of how data flows through a chip, Cycuity enables engineers to visualize and block unauthorized information paths, turning the theoretical CWE framework into an actionable engineering workflow.
Data and Efficiency Analysis
The methodology’s impact on efficiency is perhaps its most significant contribution to the industry. In traditional hardware development, security is often treated as a manual audit performed at the end of the design cycle. This approach is not only prone to human error but is also prohibitively expensive if a flaw is discovered late in the process.
According to data derived from the methodology’s application, the use of reusable templates allowed for a 40% reduction in the time required to develop security monitors for common hardware weaknesses. Furthermore, the systematic mapping of CWEs ensured 100% coverage of the defined security boundary for the X280, a feat that is difficult to guarantee with manual inspection.
The scalability of the approach also means that as the MITRE CWE list grows—currently sitting at over 100 hardware-specific weaknesses—the methodology can adapt. New templates can be added to the library, allowing companies to stay ahead of emerging threat vectors without reinventing their entire verification stack.
Broader Impact on the RISC-V Ecosystem
The implications of this methodology extend far beyond the three participating companies. As RISC-V continues to gain market share in data centers, automotive systems, and IoT devices, the ecosystem requires a standardized way to communicate security guarantees.
By moving toward a CWE-based language, the industry can move away from fragmented, vendor-specific security claims and toward a unified standard. This facilitates a "security-by-design" culture where IP providers can deliver not just the RTL code, but also a comprehensive "Security Assurance Bundle" containing the CWE mappings, verification evidence, and the golden model used for testing.
Moreover, this methodology lowers the barrier to entry for smaller firms that may not have the resources to build a dedicated hardware security team from scratch. By following the standardized framework and utilizing the templates developed through this collaboration, smaller players can ensure their designs meet global security expectations.
Conclusion and Future Outlook
The collaborative effort by Cycuity, BAE Systems, and SiFive marks a pivotal moment in the evolution of hardware security. By successfully applying a scalable, CWE-based methodology to a high-performance processor like the SiFive X280, the partners have proven that comprehensive security assurance is achievable without sacrificing engineering efficiency.
Looking forward, the goal is to see this methodology adopted as a standard practice within the RISC-V International community. As the industry moves toward more complex heterogeneous computing environments, the ability to verify the security of every IP block—regardless of its origin—will be the foundation upon which secure global infrastructure is built. The transition from reactive patching to proactive, template-based hardware assurance represents the next frontier in the ongoing battle to secure the silicon layer.
