TeamUSEC

RISC-V CPU Security | TeamUSEC

About this study

In this interview study, we explore the security considerations in the development process of open-source RISC-V CPUs, aiming to understand current best practices. Our objective is to investigate the understanding of security in open-source RISC-V CPU development, explore implemented security measures and challenges. Our aim is to identify security challenges across the ecosystem to inform future development and research.

CPU: When we use the term CPU, we often mean it synonymously with core, processor, or similar terms.

We are looking for people who

  • are currently involved in the development of open-source RISC-V CPUs, or have been involved in such development at least within the last five years
  • are 18 years or older
  • are comfortable with participation in an interview on this topic in English

Participants will

  • fill in a short preparatory questionnaire (max. 10 min)
  • book a time slot for an interview of about 60 minutes
  • answer questions on their experiences and opinions during the interview
  • be offered a compensation of USD 60 for their time. We can offer the following options:
    • Amazon vouchers for EU, US, or UK

      Please be aware that we cannot reimburse you for any transaction fees that might occur, depending on your choice of compensation.

Motivation

RISC-V is a young and rapidly growing open instruction set architecture (ISA) can be used in areas such as IoT, automotive systems, wearables, smartphones, high-performance computing, and space technologies. Many open-source RISC-V CPU projects are widely reused as reference designs in both research and industry. Since CPUs perform critical functions within computing systems, security vulnerabilities at the hardware level can have serious consequences. Unlike software issues, hardware vulnerabilities are often difficult to fix and may require costly redesigns and reintegration efforts. Despite the increasing importance of open-source RISC-V CPUs, there is still limited insight into their security development processes and how security decisions are made throughout the different stages of their lifecycle.

Study procedure and participation

We value and appreciate your contribution in our study. As briefly described above, participation includescompleting a short sign-up questionnaire (5-10 minutes), at the end of which you can freely choose an interview time from our available slots. Participation in an interview will take about 60 minutes. During the interview, we are interested in your experiences and opinions when developing RISC-V CPUs.

We are committed to participants’ privacy and confidentiality of all data you provide. We will only use short quotes from the interviews in our publication with your approval, and make sure that you cannot be identified from our reporting. After the interview, we offer a compensation of $60 for your time and effort.

If you are still interested in participating, please fill out this short questionnaire and subsequently schedule an appointment for the online interview.

Who we are

We are a research team at the CISPA Helmholtz Center for Information Security, a state-funded research center in Germany. Our research focuses on the intersection of computer security, privacy, human factors, and the low-level security of modern computer systems. In particular, we are interested in understanding how developers and designers of computer systems interact with security and privacy mechanisms, as well as how security features are integrated into hardware systems.

You can find our publications here.

Researchers

Anne Vonderheide | Researcher & PhD Student (CISPA).
Contact: anne.vonderheide@cispa.de
Alexandra von Preuschen | Researcher & PostDoc (CISPA)
Eric Ackermann | Researcher & PhD Student (CISPA)
Fabian Thomas | Researcher & PhD Student (CISPA)
Dr. Michael Schwarz | Tenured Faculty (CISPA)
Dr. Sven Bugiel | Tenured Faculty (CISPA)
Prof. Dr. Sascha Fahl | Principal Investigator, Tenured Faculty (CISPA) and Full Professor (Leibniz University Hannover)

Institutions

LUH logo

Leibniz University Hannover

CISPA logo

CISPA Helmholtz-Center for Information Security