WEBVTT

1
00:00:00.000 --> 00:00:05.320
A security conclusion must say what is
protected, which faults are assumed, which

2
00:00:05.320 --> 00:00:10.144
boundaries were tested, which
counterexamples remain, and what is unknown.

3
00:00:10.144 --> 00:00:13.450
An evidence package is not a pile of
reports;

4
00:00:13.450 --> 00:00:17.770
it lets another engineer reproduce the
result and see its limits.

5
00:00:17.770 --> 00:00:21.619
A building inspection cannot end with a
“passed” sticker;

6
00:00:21.619 --> 00:00:26.254
the reader needs the inspected floors, date,
and inaccessible rooms.

7
00:00:26.254 --> 00:00:32.512
Hardware review likewise starts from a
falsifiable claim, such as: “Under at most

8
00:00:32.512 --> 00:00:38.370
one transient upset to the saved flag, with
checker, clock, reset, and acceptance

9
00:00:38.370 --> 00:00:42.531
endpoint trusted, no unauthorized
transaction commits.

10
00:00:42.531 --> 00:00:48.462
” The analogy does not replace a product
threat model or certification.

11
00:00:48.750 --> 00:00:53.019
A claim lists asset and acceptance boundary,
attacker capabilities, fault

12
00:00:53.019 --> 00:00:57.088
target/effect/timing/budget,
trusted components, environment, design

13
00:00:57.088 --> 00:00:58.550
revision, and exclusions.

14
00:00:58.550 --> 00:01:03.259
Label evidence as requirement, RTL review,
simulation, formal, netlist,

15
00:01:03.259 --> 00:01:05.585
physical measurement, or product test.

16
00:01:05.585 --> 00:01:07.843
These levels are not interchangeable.

17
00:01:07.843 --> 00:01:10.031
Coverage is more than one percentage.

18
00:01:10.031 --> 00:01:15.062
List denominators and gaps across target ×
effect × time × lifecycle × reset/domain

19
00:01:15.062 --> 00:01:19.493
bins; include fault-free/authorized
controls, counterexamples, and replay

20
00:01:19.493 --> 00:01:23.528
hashes. Link each counterexample to root
cause, fix commit, and retest.

21
00:01:23.528 --> 00:01:28.014
Unsupported or unobservable cases are
unknown, not covered.

22
00:01:28.292 --> 00:01:34.135
Separate conclusions into “no counterexample
found in scope,” “counterexample exists,”

23
00:01:34.135 --> 00:01:37.286
“evidence missing,” and “assumption
unverified.

24
00:01:37.286 --> 00:01:39.412
” The first does not mean zero risk.

25
00:01:39.412 --> 00:01:42.050
A product owner must accept residual risk;

26
00:01:42.050 --> 00:01:43.809
a model summary cannot do so.

27
00:01:43.809 --> 00:01:49.565
Include claim ID, revision and source,
tool/command, inputs and seeds, hashes,

28
00:01:49.565 --> 00:01:53.975
classification rules, coverage matrix,
failing traces, limits,

29
00:01:53.975 --> 00:01:55.787
unknowns, owner, and date.

30
00:01:55.787 --> 00:02:00.838
Let the reviewer choose one likely challenge
to the claim, then replay both a

31
00:02:00.838 --> 00:02:03.369
counterexample and a control case.

32
00:02:03.625 --> 00:02:08.926
These are property sketches: define the
harness transaction, reset and oracle, then

33
00:02:08.926 --> 00:02:12.469
confirm sampling boundaries before binding
to the design.

34
00:02:12.469 --> 00:02:14.736
They have not been compiled or proven.

35
00:02:14.736 --> 00:02:20.353
This snippet does not prove CDC, timing,
side-channel, or physical injection

36
00:02:20.353 --> 00:02:24.542
behavior; each requires its own tool
evidence or measurement.

37
00:02:24.542 --> 00:02:30.286
Have the reviewer choose a path most likely
to falsify the claim, then replay one

38
00:02:30.286 --> 00:02:36.189
counterexample and one control. Without the
revision, inputs, seed, tool command, and

39
00:02:36.189 --> 00:02:39.540
hashes, the replay may not be the same
experiment.

40
00:02:39.540 --> 00:02:45.661
Coverage needs its denominator: which
targets, effects, windows, lifecycle states,

41
00:02:45.661 --> 00:02:49.814
and reset domains were exercised, and which
bins remain empty.

42
00:02:49.814 --> 00:02:54.281
Label evidence by level—RTL review,
simulation, formal, netlist,

43
00:02:54.281 --> 00:02:56.946
physical measurement, or product test.

44
00:02:56.946 --> 00:03:00.761
Missing or unobservable evidence stays
unknown.

45
00:03:00.761 --> 00:03:04.420
Only the accountable owner can accept
residual risk;

46
00:03:04.420 --> 00:03:07.779
a PASS in a report cannot make that
decision.

47
00:03:08.042 --> 00:03:13.441
A security claim must bound the asset,
acceptance boundary, fault capability,

48
00:03:13.441 --> 00:03:16.623
trusted components, revision, and
exclusions.

49
00:03:16.623 --> 00:03:21.745
A pass rate, tool PASS, or absence of
counterexamples does not remove coverage

50
00:03:21.745 --> 00:03:23.918
gaps or unverified assumptions.

51
00:03:23.918 --> 00:03:29.685
Link each claim to replayable evidence,
coverage denominators, failing traces,

52
00:03:29.685 --> 00:03:32.096
fixes, and the residual-risk owner.

53
00:03:32.096 --> 00:03:36.996
Ask another reviewer to replay one
counterexample and one control from the

54
00:03:36.996 --> 00:03:40.574
saved revision, hashes, commands, inputs,
and seeds.

55
00:03:40.574 --> 00:03:43.864
Check coverage bins, limits, and unknowns.

56
00:03:43.864 --> 00:03:47.768
If evidence is missing, narrow the claim and
record the gap.

57
00:03:47.768 --> 00:03:51.984
The accountable owner decides whether to
accept residual risk.

58
00:03:51.984 --> 00:03:56.432
Documentation and model evidence support
only the stated scope;

59
00:03:56.432 --> 00:04:01.143
they do not replace product validation,
certification, or risk decisions.

60
00:04:01.143 --> 00:04:03.498
Choose an unverified CDC assumption.

61
00:04:03.498 --> 00:04:07.472
What minimum evidence would support it, and
who will provide it?

62
00:04:07.472 --> 00:04:09.928
Which gaps must block release?

63
00:04:09.928 --> 00:04:14.435
Preserve revision records so the next fix
and retest can be compared

64
00:04:14.435 --> 00:04:16.604
under the same conditions.
