The NSA has published two technical reports on the hardware security of ASIC (Application-Specific Integrated Circuit) design, aiming to standardize manufacture and development.
ASICs Best Practices Threat Catalog
The Threat Catalog aims to protect ASICs from hardware compromise. Interestingly, it addresses protection against physical side-channel analysis – a key area of research and expertise for PQShield.
Post-quantum cryptography is particularly susceptible to side-channel attack, and the threat catalog forces designers to ensure that physical layout protections cannot be stripped, weakened, or bypassed during chip development.
There are further implications for PQC-readiness in ASIC design. For example, the Threat Catalog establishes that pre-packaged cryptographic IP, or 3PIP (Third-Party Intellectual Property) must be treated as ‘untrusted’, requiring an independent verification, as well as further measures, to ensure a rogue IP core cannot read private lattice keys. It brings a sharp focus to the hardware supply chain: licensed IP must be verified and sandboxed directly, ensuring chipmakers turn to proven, audited providers.
ASICs Level of Assurance (LoA1)
LoA1 applies to ASIC-based designs that could impact US Government capabilities. It transforms generic hardware guidelines into actionable requirements, forcing engineers and foundries into best practice when it comes to mitigating the threats outlined in the Threat Catalog.
It formalizes accountability in the supply chain, meaning that chipmakers must implement rigorous tracking, IP inspection, source-code audits and liability standards.
There are implications for design. For example, LoA1 mandates reconciliation checks on post-tapeout layout to preserve side-channel countermeasures, controls over test-bench hardware environments and isolated memory regions for storing private lattice keys during encapsulation and digital signing.
PQShield sits at the intersection of PQC algorithms, hardware IP licensing and side-channel and fault protection. It’s fascinating to see how the US is considering quantum-readiness as a key part of its strategy for ASIC design – reinforcing the message that updating silicon for the post-quantum age is just as important as updating the algorithms that use it.