In this interview study, we explore the security considerations in the development process of open-source RISC-V CPUs, aiming to understand current best practices. Our objective is to investigate the understanding of security in open-source RISC-V CPU development, explore implemented security measures and challenges. Our aim is to identify security challenges across the ecosystem to inform future development and research.
CPU:
When we use the term CPU, we often mean it synonymously with core, processor, or similar terms.
We are looking for people who
are currently involved in the development of open-source RISC-V CPUs, or have been involved in such development at least within the last five years
are 18 years or older
are comfortable with participation in an interview on this topic in English
Participants will
fill in a short preparatory questionnaire (max. 10 min)
book a time slot for an interview of about 60 minutes
answer questions on their experiences and opinions during the interview
be offered a compensation of USD 60 for their time. We can offer the following options:
Amazon vouchers for EU, US, or UK
Please be aware that we cannot reimburse you for any transaction fees that might occur, depending on your choice of compensation.
Motivation
RISC-V is a young and rapidly growing open instruction set architecture (ISA) can be used in areas such as IoT, automotive systems, wearables, smartphones, high-performance computing, and space technologies. Many open-source RISC-V CPU projects are widely reused as reference designs in both research and industry. Since CPUs perform critical functions within computing systems, security vulnerabilities at the hardware level can have serious consequences. Unlike software issues, hardware vulnerabilities are often difficult to fix and may require costly redesigns and reintegration efforts. Despite the increasing importance of open-source RISC-V CPUs, there is still limited insight into their security development processes and how security decisions are made throughout the different stages of their lifecycle.
Study procedure and participation
We value and appreciate your contribution in our study. As briefly described above, participation includescompleting a short sign-up questionnaire (5-10 minutes), at the end of which you can freely choose an interview time from our available slots. Participation in an interview will take about 60 minutes. During the interview, we are interested in your experiences and opinions when developing RISC-V CPUs.
We are committed to participants’ privacy and confidentiality of all data you provide. We will only use short quotes from the interviews in our publication with your approval, and make sure that you cannot be identified from our reporting. After the interview, we offer a compensation of $60 for your time and effort.
If you are still interested in participating, please fill out this short questionnaire and subsequently schedule an appointment for the online interview.
Who we are
We are a research team at the CISPA Helmholtz Center for Information Security, a state-funded research center in Germany. Our research focuses on the intersection of computer security, privacy, human factors, and the low-level security of modern computer systems. In particular, we are interested in understanding how developers and designers of computer systems interact with security and privacy mechanisms, as well as how security features are integrated into hardware systems.