Structuring Trust: A Quantitative and Traceable Framework for Hardware Security Assurance | Research Square window.SnipcartSettings = { analytics: { enabled: false } }; (function() { var accessVector = localStorage.getItem('access_vector') || ''; window.dataLayer = window.dataLayer || []; if (accessVector) { window.dataLayer.push({ user: { profile: { profileInfo: { snid: accessVector } } } }); } })(); (function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start':new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0],j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src='https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);})(window,document,'script','dataLayer','GTM-K279D39R'); Browse Preprints In Review Journals COVID-19 Preprints AJE Video Bytes Research Tools Research Promotion AJE Professional Editing AJE Rubriq About Preprint Platform In Review Editorial Policies Our Team Advisory Board Help Center Sign In Submit a Preprint Cite Share Download PDF Research Article Structuring Trust: A Quantitative and Traceable Framework for Hardware Security Assurance Shao-Fang Wen, Arvind Sharma This is a preprint; it has not been peer reviewed by a journal. https://doi.org/ 10.21203/rs.3.rs-8099540/v1 This work is licensed under a CC BY 4.0 License Status: Under Review Version 1 posted 14 You are reading this latest preprint version Abstract The security assurance of hardware systems is increasingly critical in connected and safety-sensitive infrastructures, where compromised components can endanger human safety or disrupt essential services. However, current assurance practices remain largely qualitative and fragmented across overlapping standards, leading to duplicated evaluation efforts and inconsistent interpretations of system trustworthiness. This paper introduces a structured, multi-level framework that links security requirements to verification evidence through six traceable layers, enabling reproducible and partially quantitative assessment of hardware assurance. The framework supports lifecycle reasoning and transparent traceability, allowing assurance arguments to be consolidated across complex, multi-component systems. Its applicability is demonstrated through a wireless fingertip oximeter used in healthcare infrastructure, illustrating how traceable evidence and quantitative scoring can provide measurable subsystem evaluation and diagnostic insight into system-level resilience. Hardware security assurance Quantitative assurance Security metrics Security evaluation Full Text Additional Declarations No competing interests reported. Cite Share Download PDF Status: Under Review Version 1 posted Editorial decision: Revision requested 02 Mar, 2026 Reviews received at journal 06 Feb, 2026 Reviews received at journal 31 Jan, 2026 Reviews received at journal 25 Jan, 2026 Reviews received at journal 23 Jan, 2026 Reviewers agreed at journal 14 Jan, 2026 Reviewers agreed at journal 14 Jan, 2026 Reviewers agreed at journal 09 Jan, 2026 Reviewers agreed at journal 09 Jan, 2026 Reviewers agreed at journal 08 Jan, 2026 Reviewers invited by journal 06 Jan, 2026 Editor assigned by journal 13 Nov, 2025 Submission checks completed at journal 13 Nov, 2025 First submitted to journal 12 Nov, 2025 You are reading this latest preprint version Research Square lets you share your work early, gain feedback from the community, and start making changes to your manuscript prior to peer review in a journal. As a division of Research Square Company, we’re committed to making research communication faster, fairer, and more useful. We do this by developing innovative software and high quality services for the global research community. Our growing team is made up of researchers and industry professionals working together to solve the most critical problems facing scientific publishing. Also discoverable on Platform About Our Team In Review Editorial Policies Advisory Board Help Center Resources Author Services Accessibility API Access RSS feed Manage Cookie Preferences © Research Square 2026 | ISSN 2693-5015 (online) Privacy Policy Terms of Service Do Not Sell My Personal Information {"props":{"pageProps":{"initialData":{"identity":"rs-8099540","acceptedTermsAndConditions":true,"allowDirectSubmit":false,"archivedVersions":[],"articleType":"Research Article","associatedPublications":[],"authors":[{"id":572604043,"identity":"a500572e-6410-4a68-b29d-34ca92daff64","order_by":0,"name":"Shao-Fang Wen","email":"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAZAAAAAyAQMAAABI0h/eAAAABlBMVEX///8AAABVwtN+AAAACXBIWXMAAA7EAAAOxAGVKw4bAAAA4UlEQVRIiWNgGAWjYDACCRBhA+NVEK0lDcY7A+GToIWxjQgt8rObHz5gSLDLk3fgMXxcOO9OnblEAtuDD3i0GNw5ZmzAkJBcbHiAx9h45rZnEpYzEtgNZ+DTIpFgJv33B3PixgbebdK82w5LGNxIYJPmweewGenfJBgS6kFatv/mnUOEFoYbOWZALYcT5zPwbmPmbSBCi8GNnGKgX44nbmDm/yzNc+yw5IYzD9sk8fkF6LCNwBCrTpzf3pb4mafmML/B8eRjEvhCDGHdYTiTsYEYDUDriFQ3CkbBKBgFIxAAAObHSJE/N36NAAAAAElFTkSuQmCC","orcid":"","institution":"University of South-Eastern Norway","correspondingAuthor":true,"prefix":"","firstName":"Shao-Fang","middleName":"","lastName":"Wen","suffix":""},{"id":572604045,"identity":"4f8ca6dd-1320-4dd3-ab46-d861004fa34d","order_by":1,"name":"Arvind Sharma","email":"","orcid":"","institution":"Norwegian University of Science and Technology","correspondingAuthor":false,"prefix":"","firstName":"Arvind","middleName":"","lastName":"Sharma","suffix":""}],"badges":[],"createdAt":"2025-11-12 20:23:12","currentVersionCode":1,"declarations":"","doi":"10.21203/rs.3.rs-8099540/v1","doiUrl":"https://doi.org/10.21203/rs.3.rs-8099540/v1","draftVersion":[],"editorialEvents":[],"editorialNote":"","failedWorkflow":false,"files":[{"id":100360322,"identity":"7f44e258-3645-48a3-b78b-06681e4cd35d","added_by":"auto","created_at":"2026-01-16 07:38:23","extension":"docx","order_by":0,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":1871076,"visible":true,"origin":"","legend":"","description":"","filename":"manuscriptv1.0.docx","url":"https://assets-eu.researchsquare.com/files/rs-8099540/v1/d9a4ad4e4cb2a6a29e957fbe.docx"},{"id":99999333,"identity":"dfba9ca1-4ef2-4abb-ab74-c04ca0fcd357","added_by":"auto","created_at":"2026-01-12 03:55:46","extension":"json","order_by":1,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":4041,"visible":true,"origin":"","legend":"","description":"","filename":"cf0b457baafd46a7ab2c322debc9ec92.json","url":"https://assets-eu.researchsquare.com/files/rs-8099540/v1/ed1490a82c6154016bb8cb89.json"},{"id":100360781,"identity":"2f7baf2d-5f0e-4638-b505-437888e6552a","added_by":"auto","created_at":"2026-01-16 07:43:43","extension":"xml","order_by":2,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":215100,"visible":true,"origin":"","legend":"","description":"","filename":"cf0b457baafd46a7ab2c322debc9ec921enriched.xml","url":"https://assets-eu.researchsquare.com/files/rs-8099540/v1/914bd7c92b4f4a0bf1a96d52.xml"},{"id":99999352,"identity":"4b4b4d6c-167b-4e14-a907-276f0cabe276","added_by":"auto","created_at":"2026-01-12 03:55:47","extension":"png","order_by":3,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":54522,"visible":true,"origin":"","legend":"","description":"","filename":"floatimage1.png","url":"https://assets-eu.researchsquare.com/files/rs-8099540/v1/7e323cf4410f7e2826160e0d.png"},{"id":99999334,"identity":"cca00f72-56a5-4e8b-ae63-cf7e438889ed","added_by":"auto","created_at":"2026-01-12 03:55:46","extension":"png","order_by":4,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":56840,"visible":true,"origin":"","legend":"","description":"","filename":"floatimage2.png","url":"https://assets-eu.researchsquare.com/files/rs-8099540/v1/89a8effeffe7d09ae9198778.png"},{"id":100360282,"identity":"b892ac99-108c-4c58-8b4c-de0b15dc04b0","added_by":"auto","created_at":"2026-01-16 07:38:15","extension":"png","order_by":5,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":84790,"visible":true,"origin":"","legend":"","description":"","filename":"floatimage3.png","url":"https://assets-eu.researchsquare.com/files/rs-8099540/v1/4d76330cc4f3596f8ce89aee.png"},{"id":99999354,"identity":"b2f12fd9-360a-4f11-906b-de8ba88f0843","added_by":"auto","created_at":"2026-01-12 03:55:47","extension":"png","order_by":6,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":1353925,"visible":true,"origin":"","legend":"","description":"","filename":"floatimage4.png","url":"https://assets-eu.researchsquare.com/files/rs-8099540/v1/8aefa7acc41ee1ad1cb78610.png"},{"id":99999353,"identity":"699e57c1-693e-43e5-9ddc-45cd65fcef93","added_by":"auto","created_at":"2026-01-12 03:55:47","extension":"png","order_by":7,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":76633,"visible":true,"origin":"","legend":"","description":"","filename":"floatimage5.png","url":"https://assets-eu.researchsquare.com/files/rs-8099540/v1/ac7be269b84aba14cf9a037f.png"},{"id":100361306,"identity":"258c6421-53a1-4a15-8b89-a819d7b433f9","added_by":"auto","created_at":"2026-01-16 07:44:52","extension":"png","order_by":8,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":41389,"visible":true,"origin":"","legend":"","description":"","filename":"floatimage6.png","url":"https://assets-eu.researchsquare.com/files/rs-8099540/v1/3e19d1820b325b9532a34e9c.png"},{"id":100360641,"identity":"1cfd7936-43bb-4ed3-8588-4fa241b7254f","added_by":"auto","created_at":"2026-01-16 07:40:34","extension":"png","order_by":9,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":38193,"visible":true,"origin":"","legend":"","description":"","filename":"floatimage7.png","url":"https://assets-eu.researchsquare.com/files/rs-8099540/v1/bc770204f8ed9d32db220c0e.png"},{"id":99999336,"identity":"dfc67692-0988-4591-82f2-027ed47bb96e","added_by":"auto","created_at":"2026-01-12 03:55:46","extension":"png","order_by":10,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":36177,"visible":true,"origin":"","legend":"","description":"","filename":"floatimage8.png","url":"https://assets-eu.researchsquare.com/files/rs-8099540/v1/138576227aae0dd046da1c32.png"},{"id":100360581,"identity":"7ee80387-e379-407e-9832-3d932162936e","added_by":"auto","created_at":"2026-01-16 07:39:35","extension":"png","order_by":11,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":20879,"visible":true,"origin":"","legend":"","description":"","filename":"Onlinefloatimage1.png","url":"https://assets-eu.researchsquare.com/files/rs-8099540/v1/7df4f4aeaacf9ef69876b655.png"},{"id":99999349,"identity":"6ff49b54-8028-49b5-b8a5-c7e5d2844a6f","added_by":"auto","created_at":"2026-01-12 03:55:46","extension":"png","order_by":12,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":22558,"visible":true,"origin":"","legend":"","description":"","filename":"Onlinefloatimage2.png","url":"https://assets-eu.researchsquare.com/files/rs-8099540/v1/c12bc876128b8fc87e7d3169.png"},{"id":100361302,"identity":"ed313a17-8f42-4c4b-b022-a829111eaaef","added_by":"auto","created_at":"2026-01-16 07:44:51","extension":"png","order_by":13,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":44233,"visible":true,"origin":"","legend":"","description":"","filename":"Onlinefloatimage3.png","url":"https://assets-eu.researchsquare.com/files/rs-8099540/v1/2744c12c27a47a9d6169cd30.png"},{"id":99999346,"identity":"28cbfa42-6063-4bc4-895b-8d87ddc381d4","added_by":"auto","created_at":"2026-01-12 03:55:46","extension":"png","order_by":14,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":96366,"visible":true,"origin":"","legend":"","description":"","filename":"Onlinefloatimage4.png","url":"https://assets-eu.researchsquare.com/files/rs-8099540/v1/fb4755817088f5c8b6914e13.png"},{"id":99999341,"identity":"aaa9d3ec-e5cb-4ebb-9ac0-3d1b83ee0a1c","added_by":"auto","created_at":"2026-01-12 03:55:46","extension":"png","order_by":15,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":23565,"visible":true,"origin":"","legend":"","description":"","filename":"Onlinefloatimage5.png","url":"https://assets-eu.researchsquare.com/files/rs-8099540/v1/bf6384e1f3e46c3f2465e4ba.png"},{"id":99999338,"identity":"1b5f3300-2a93-4f31-92b5-1b7784c9d31b","added_by":"auto","created_at":"2026-01-12 03:55:46","extension":"png","order_by":16,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":14546,"visible":true,"origin":"","legend":"","description":"","filename":"Onlinefloatimage6.png","url":"https://assets-eu.researchsquare.com/files/rs-8099540/v1/08c309a38eac5f56e04cf2fb.png"},{"id":99999344,"identity":"c586d424-ab6b-4edb-8726-2277b691213a","added_by":"auto","created_at":"2026-01-12 03:55:46","extension":"png","order_by":17,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":14073,"visible":true,"origin":"","legend":"","description":"","filename":"Onlinefloatimage7.png","url":"https://assets-eu.researchsquare.com/files/rs-8099540/v1/a0599609c249156e78628b5a.png"},{"id":100361042,"identity":"62296f1a-83c9-439a-9814-b08700339df4","added_by":"auto","created_at":"2026-01-16 07:44:20","extension":"png","order_by":18,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":13847,"visible":true,"origin":"","legend":"","description":"","filename":"Onlinefloatimage8.png","url":"https://assets-eu.researchsquare.com/files/rs-8099540/v1/796217c5518796f0111c8f51.png"},{"id":99999348,"identity":"3a70d757-2677-4467-a7d3-7bd7baaa25a6","added_by":"auto","created_at":"2026-01-12 03:55:46","extension":"xml","order_by":19,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":214305,"visible":true,"origin":"","legend":"","description":"","filename":"cf0b457baafd46a7ab2c322debc9ec921structuring.xml","url":"https://assets-eu.researchsquare.com/files/rs-8099540/v1/65edbaa44d69f85e19baf9de.xml"},{"id":99999345,"identity":"2fcddf4b-51ea-4f91-b1ae-eb51cd3009d1","added_by":"auto","created_at":"2026-01-12 03:55:46","extension":"html","order_by":20,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":233261,"visible":true,"origin":"","legend":"","description":"","filename":"earlyproof.html","url":"https://assets-eu.researchsquare.com/files/rs-8099540/v1/92abc20def48bdbd5ef7cf26.html"},{"id":100406491,"identity":"f4ad590c-fb5a-4efb-9297-3d5d04c1a919","added_by":"auto","created_at":"2026-01-16 13:02:38","extension":"pdf","order_by":1,"title":"","display":"","copyAsset":false,"role":"manuscript-pdf","size":1062128,"visible":true,"origin":"","legend":"","description":"","filename":"manuscriptv1.0.pdf","url":"https://assets-eu.researchsquare.com/files/rs-8099540/v1_covered_9127b444-7f21-499a-a571-4032d2a42309.pdf"}],"financialInterests":"No competing interests reported.","formattedTitle":"Structuring Trust: A Quantitative and Traceable Framework for Hardware Security Assurance","fulltext":[],"fulltextSource":"","fullText":"","funders":[],"hasAdminPriorityOnWorkflow":false,"hasManuscriptDocX":false,"hasOptedInToPreprint":true,"hasPassedJournalQc":"","hasAnyPriority":false,"hideJournal":false,"highlight":"","institution":"","isAcceptedByJournal":false,"isAuthorSuppliedPdf":true,"isDeskRejected":"","isHiddenFromSearch":false,"isInQc":false,"isInWorkflow":false,"isPdf":true,"isPdfUpToDate":true,"isWithdrawnOrRetracted":false,"journal":{"display":true,"email":"
[email protected]","identity":"international-journal-of-information-security","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":false,"externalIdentity":"ijis","sideBox":"Learn more about [International Journal of Information Security](http://link.springer.com/journal/10207)","snPcode":"10207","submissionUrl":"https://submission.nature.com/new-submission/10207/3","title":"International Journal of Information Security","twitterHandle":"","acdcEnabled":true,"dfaEnabled":true,"editorialSystem":"em","reportingPortfolio":"Springer Hybrid","inReviewEnabled":true,"inReviewRevisionsEnabled":false},"keywords":"Hardware security assurance, Quantitative assurance, Security metrics, Security evaluation","lastPublishedDoi":"10.21203/rs.3.rs-8099540/v1","lastPublishedDoiUrl":"https://doi.org/10.21203/rs.3.rs-8099540/v1","license":{"name":"CC BY 4.0","url":"https://creativecommons.org/licenses/by/4.0/"},"manuscriptAbstract":"\u003cp\u003eThe security assurance of hardware systems is increasingly critical in connected and safety-sensitive infrastructures, where compromised components can endanger human safety or disrupt essential services. However, current assurance practices remain largely qualitative and fragmented across overlapping standards, leading to duplicated evaluation efforts and inconsistent interpretations of system trustworthiness. This paper introduces a structured, multi-level framework that links security requirements to verification evidence through six traceable layers, enabling reproducible and partially quantitative assessment of hardware assurance. The framework supports lifecycle reasoning and transparent traceability, allowing assurance arguments to be consolidated across complex, multi-component systems. Its applicability is demonstrated through a wireless fingertip oximeter used in healthcare infrastructure, illustrating how traceable evidence and quantitative scoring can provide measurable subsystem evaluation and diagnostic insight into system-level resilience.\u003c/p\u003e","manuscriptTitle":"Structuring Trust: A Quantitative and Traceable Framework for Hardware Security Assurance","msid":"","msnumber":"","nonDraftVersions":[{"code":1,"date":"2026-01-12 03:55:41","doi":"10.21203/rs.3.rs-8099540/v1","editorialEvents":[{"type":"communityComments","content":0},{"type":"decision","content":"Revision requested","date":"2026-03-02T23:54:36+00:00","index":"","fulltext":""},{"type":"editorInvitedReview","content":"","date":"2026-02-06T08:35:20+00:00","index":"hide","fulltext":""},{"type":"editorInvitedReview","content":"","date":"2026-02-01T00:36:33+00:00","index":"hide","fulltext":""},{"type":"editorInvitedReview","content":"","date":"2026-01-25T07:54:59+00:00","index":"hide","fulltext":""},{"type":"editorInvitedReview","content":"","date":"2026-01-24T01:05:03+00:00","index":"hide","fulltext":""},{"type":"reviewerAgreed","content":"292165555198144995533378334557628303106","date":"2026-01-14T14:57:27+00:00","index":"hide","fulltext":""},{"type":"reviewerAgreed","content":"78517923206494830976035454965835063687","date":"2026-01-14T09:43:34+00:00","index":"hide","fulltext":""},{"type":"reviewerAgreed","content":"65988486819690380768668018362326724674","date":"2026-01-09T11:02:34+00:00","index":"hide","fulltext":""},{"type":"reviewerAgreed","content":"324089353947732331160307098907003978201","date":"2026-01-09T10:51:37+00:00","index":"hide","fulltext":""},{"type":"reviewerAgreed","content":"267568959659788666718158065469513940565","date":"2026-01-08T20:05:35+00:00","index":"hide","fulltext":""},{"type":"reviewersInvited","content":"","date":"2026-01-06T16:34:33+00:00","index":"","fulltext":""},{"type":"editorAssigned","content":"","date":"2025-11-13T06:38:30+00:00","index":"","fulltext":""},{"type":"checksComplete","content":"","date":"2025-11-13T06:38:04+00:00","index":"","fulltext":""},{"type":"submitted","content":"International Journal of Information Security","date":"2025-11-12T20:14:56+00:00","index":"","fulltext":""}],"status":"published","journal":{"display":true,"email":"
[email protected]","identity":"international-journal-of-information-security","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":false,"externalIdentity":"ijis","sideBox":"Learn more about [International Journal of Information Security](http://link.springer.com/journal/10207)","snPcode":"10207","submissionUrl":"https://submission.nature.com/new-submission/10207/3","title":"International Journal of Information Security","twitterHandle":"","acdcEnabled":true,"dfaEnabled":true,"editorialSystem":"em","reportingPortfolio":"Springer Hybrid","inReviewEnabled":true,"inReviewRevisionsEnabled":false}}],"origin":"","ownerIdentity":"096c4969-af1c-49a9-b5a3-a1cd152fdc4a","owner":[],"postedDate":"January 12th, 2026","published":true,"recentEditorialEvents":[],"rejectedJournal":[],"revision":"","amendment":"","status":"under-review","subjectAreas":[],"tags":[],"updatedAt":"2026-03-17T07:59:55+00:00","versionOfRecord":[],"versionCreatedAt":"2026-01-12 03:55:41","video":"","vorDoi":"","vorDoiUrl":"","workflowStages":[]},"version":"v1","identity":"rs-8099540","journalConfig":"researchsquare"},"__N_SSP":true},"page":"/article/[identity]/[[...version]]","query":{"redirect":"/article/rs-8099540","identity":"rs-8099540","version":["v1"]},"buildId":"XKTyCvWXoU3ODBz1xrDgd","isFallback":false,"isExperimentalCompile":false,"dynamicIds":[84888],"gssp":true,"scriptLoader":[]}
Text is read by the "Ask this paper" AI Q&A widget below.
Extraction quality varies by source — PMC NXML preserves structure
cleanly, OA-HTML may include some navigation residue, and OA-PDF can
have broken hyphenation. The publisher copy
(via DOI)
is the canonical version.