Bastion: Fortifying Network on Chip

Francesco Restuccia recently presented our research project “BASTION: A Framework for Secure Third-Party IP Integration in NoC-based SoC Platforms” at the Conference on Cryptographic Hardware and Embedded Systems (CHES) 2025 in Kuala Lumpur, Malaysia.

BASTION addresses one of the most critical challenges in hardware security: access control. Access control vulnerabilities appear in 5 out of 11 entries on 2025 MITRE’s list of most important hardware CWEs. By combining hardware design with rigorous security verification, BASTION provides a comprehensive framework for building provably verifiable access control systems on NoC-based platforms.

BASTION is a collaborative project, and it would not have been possible without the key contributions of Zhenghua Ma and Andres Meza from our UCSD hardware security team, together with Joseph Zuckerman, Biruk Seyoum, and Luca Carloni from Columbia University.

BASTION is integrated with the ESP platform and is open-source. Check out our GitHub repo and paper.