Meaning
Assurance certification defines the highest level of security verification for high-risk industrial hardware where software protection against sophisticated penetration attacks must withstand rigorous scrutiny. A common criteria eal6 designation indicates that a device design exhibits semi-formally verified security architecture that prevents intentional manipulation by attackers with high motivation and substantial technical resources. This level moves beyond standard documentation to mandate a structured analysis of the entire hardware implementation for potential covert channels and hardware trojans.
Security Assessment
Verification involves a complete mapping of the security functional requirements to the underlying physical layout of the integrated circuit. Testing at this intensity requires access to the complete design database and the gate-level netlist to trace every signal flow path. Evaluators simulate malicious perturbations of the hardware state to confirm that the logic maintains integrity under extreme stress conditions.
Failure in any single gate path or logical interface results in a rejection of the certification claim for the entire product line.
Component Integration
Hardware modules seeking this status undergo an independent review of the supply chain to ensure that the manufacturing process does not introduce undocumented features. Engineers perform physical inspections of the silicon die to confirm that the physical routing matches the verified schematic files exactly. System integrators incorporate these certified units into critical infrastructure such as hardware security modules or secure crypto processors to establish a foundation of trust.
Procurement of such components ensures that the hardware portion of the secure boundary provides a verifiable defense against side-channel analysis and physical tampering attempts.
Certification Constraint
Application of these rules restricts the development speed of electronic systems because the formal verification of every logical gate demands exhaustive computational time. Design cycles for these products stretch over years rather than months due to the complexity of the semi-formal proof requirements. Manufacturers must commit to a rigid development path that limits the choice of available fabrication facilities to those capable of providing the necessary traceability.
High costs associated with the evaluation process limit the adoption of this security grade to niche hardware modules deployed in military or government intelligence environments.