Solutions you can trust in the worst case scenarios.
We protect systems against modern attacks and tampering attempts to ensure security and operational capabilities under all circumstances.
Crosshill also offers advanced security testing services to evaluate the overall security level of electronic systems and devices. State-of-the-art passive and active testing methods are applied to both semiconductor and board level security assessments.
> Start the conversation. Let’s build security you can rely on.
- > Schematic design
- > Layout design
- > FPGA design
- > Mechanical design
- > Low-level firmware
- > Embedded software
- > Protocols and algorithms
- > Digital signal processing
- > Side-channel analysis
- > Fault injection analysis
- > Electromagnetic testing
- > Reverse engineering
- > PCB and PCBA
- > Sourcing
- > Assembly
- > Crypto provisioning
- > Schematic design
- > Layout design
- > FPGA design
- > Mechanical design
- > Low-level firmware
- > Embedded software
- > Protocols and algorithms
- > Digital signal processing
- > Side-channel analysis
- > Fault injection analysis
- > Electromagnetic testing
- > Reverse engineering
- > PCB and PCBA
- > Sourcing
- > Assembly
- > Crypto provisioning
Our mission at Crosshill is simple:
provide our customers with fully secured embedded solutions.

Hardware Design
Crosshill has extensive experience in advanced microelectronics that lay the foundation for highly secure communication systems and cryptographic equipment.
Anti-tamper services focus on silicon, sensor, and mechanical level protection mechanisms to safeguard classified information and sensitive IPs.
> Schematic Design
Schematic design consists of components selections, library creation, pin mapping, and finally actual schematic design by creating connections between the power planes, ground planes, general purpose inputs and outputs, high-speed signals and other special signals.
Typical output files are schematic sheets and bill of material. Simulation tools can be used to emulate functional behavior of circuitries, which typically saves lots of time and money, without the need for actual hardware yet. Simulations are used at this stage typically in analog and digital simulations.
> Layout Design
Layout design follows schematic completion and focuses on placing components within the defined PCB geometry, stack-up, and floor plan.
It also ensures seamless electro-mechanical integration through collaboration between PCB and mechanical engineers, aligning the board with enclosures, connectors, cables, and mounting constraints.
Deliverables typically include Gerber files, assembly drawings, and 3D board models, supported by advanced simulations for power integrity, signal integrity, EMC compliance, and RF performance.
> Layout Design
Layout design follows schematic completion and focuses on placing components within the defined PCB geometry, stack-up, and floor plan.
It also ensures seamless electro-mechanical integration through collaboration between PCB and mechanical engineers, aligning the board with enclosures, connectors, cables, and mounting constraints.
Deliverables typically include Gerber files, assembly drawings, and 3D board models, supported by advanced simulations for power integrity, signal integrity, EMC compliance, and RF performance.
> Layout Design
Layout design follows schematic completion and focuses on placing components within the defined PCB geometry, stack-up, and floor plan.
It also ensures seamless electro-mechanical integration through collaboration between PCB and mechanical engineers, aligning the board with enclosures, connectors, cables, and mounting constraints.
Deliverables typically include Gerber files, assembly drawings, and 3D board models, supported by advanced simulations for power integrity, signal integrity, EMC compliance, and RF performance.
Schematic design consists of components selections, library creation, pin mapping, and finally actual schematic design by creating connections between the power planes, ground planes, general purpose inputs and outputs, high-speed signals and other special signals.
Typical output files are schematic sheets and bill of material. Simulation tools can be used to emulate functional behavior of circuitries, which typically saves lots of time and money, without the need for actual hardware yet. Simulations are used at this stage typically in analog and digital simulations.
Layout design follows schematic completion and focuses on placing components within the defined PCB geometry, stack-up, and floor plan.
It also ensures seamless electro-mechanical integration through collaboration between PCB and mechanical engineers, aligning the board with enclosures, connectors, cables, and mounting constraints.
Deliverables typically include Gerber files, assembly drawings, and 3D board models, supported by advanced simulations for power integrity, signal integrity, EMC compliance, and RF performance.
Field-programmable gate arrays (FPGAs) are reconfigurable circuits built for high-speed digital logic and real-time parallel processing.
They handle large data volumes efficiently while delivering predictable hardware-level performance and stronger resistance to side-channel attacks than software-based systems.
Positioned between fixed-function ASICs and programmable processors, FPGAs combine performance, security, and post-deployment flexibility through reconfigurable updates and feature patches. Typical outputs include synthesized IP blocks.
Mechanical design integrates all system components: PCBs, enclosure, cables, connectors, and interfaces, while defining materials, coatings, and markings.
It also addresses thermal management, tamper resistance, shock and vibration durability, and reliable operation in harsh environments such as high humidity or salt exposure.
These features can be simulated and validated. Typical outputs include CAD models, assembly and manufacturing drawings, and bills of materials.
Software Design
Software makes hardware fully functional and forms a glue between the device and user experience. Software is managed in several layers, but the user sees only the top surface. Secure software must be maintained and updated securely too, while vulnerability management must be handled throughout the product lifecycle.
> Low-level firmware
Firmware is the lowest level software layer that controls the microelectronics, integrated circuits and logics. This requires target specific know-how on hardware peripherals, register controls and integrated security features. If the security is lost in this layer, it cannot be patched on higher levels. For microcontroller and system-on-chips C is our preferred development language, and for FPGAs it’s VHDL or Verilog. FPGA is an intermediate technology between fixed ASIC and software processors, creating a building block for the most secure applications.
> Embedded Software
When we move one level up from hardware, we found middleware and application specific software layers. These are typically independent from the hardware and firmware layers, making them modular and highly usable whatever the used hardware target is. Security is highly important also on these layers, and it’s used together with the integrated secure features of microelectronics, to achieve the optimum solutions and overall security.
> Protocols and algorithms
Protocols and algorithms are a set of bit and byte patterns to represent or process data. In security critical applications several types of protocols and algorithms are used, such as symmetric cryptographic algorithms, hash function, key derivation function, cryptographically true random number generators, network protocols, and key negotiation protocols together with he asymmetric cryptographic algorithms.
> Digital signal processing
Digital signal processing algorithms are mathematically specified functions to execute certain operations in real-time or non-real time.
Digital signal processing is used for example in noise filtering, spectrum analysis and voice compression. Let’s say we want to send recorded audio in real-time via secure communication channel, the audio signal must be first digitized, filtered and compressed, before encryption and actual data transmission.
Firmware is the foundation of every embedded system, directly controlling microelectronics, integrated circuits, and hardware logic. It requires deep expertise in hardware peripherals, registers, and built-in security features.
Security must be established at this level—it cannot be added later. We develop firmware in C for microcontrollers and SoCs, and in VHDL or Verilog for FPGAs, which combine the security of ASICs with the flexibility of programmable hardware.
Embedded software builds on the hardware and firmware layers, providing middleware and application-specific functionality. These modular software layers are largely hardware-independent, making them portable across multiple platforms.
Security is integrated throughout the software stack and works together with hardware security features to deliver reliable, resilient, and secure embedded systems.
Protocols and algorithms define how data is processed, protected, and exchanged throughout a system. Security-critical applications rely on symmetric and asymmetric cryptography, hash functions, key derivation, true random number generation, and secure communication protocols.
Together, these technologies provide authentication, secure key exchange, data integrity, and confidential communication across embedded and networked systems.
Digital signal processing (DSP) uses mathematical algorithms to process digital signals in real time or offline. Common applications include noise reduction, spectrum analysis, voice compression, and other signal optimization tasks.
For secure communications, signals are typically digitized, filtered, compressed, and processed before encryption and transmission, ensuring both efficient performance and robust security.
Security Testing
Security Testing procedures are mandatory to make products secure. It supports our own engineering and product development activities, but it helps also our clients to identify segments where the security can be improved.
> Side-channel analysis
Side-channel analysis (SCA) is a specialized testing method to evaluate if the device leaks sensitive information via it’s side-channels such as current consumption, electromagnetic radiation, audio spectrum and temperature changes, or even mechanical vibrations. Side-channel analysis is used especially to evaluate cryptographic systems and whether their keys can be broken with the repeated trace measurements and analysis. SCA is used for both symmetric and asymmetric cryptographic algorithms, and various test methods are available such as test vector leakage assessment (TVLA), correlation power analysis (CPA), simple power analysis (SPA), or differential power analysis (DPA). The nature or side-channel analysis is non-invasive. Countermeasures against side-channel measures shall be implement to make trace-based measurements immune to reveal cryptographically sensitive material.
> Fault injection analysis
As its name itself indicates, the purpose of the fault injection attack is to manipulate the target system, such as microcontroller, System-on-Chip or FPGA, in a way that it’s going on a faulty or non-defined state. The method is used to bypass security fuses, security checks or bootloaders. Semi-invasive testing methods cover voltage and electromagnetic glitches, while laser-based glitches are typically invasive. Fault injection countermeasure shall be implemented to increase the overall security against the described attach methods.
> Electromagnetic testing
Electromagnetic testing focuses typically on information analysis via wireless communication or with the EMC aspects on the conductive and radiation emission analysis of the device itself. Information of wireless communication protocols starts with the selected modulation techniques, which form bit patters transmitting information. The bit patterns forms protocol frames with forward error correction methods, interleaving, checksum, encryption to form the complete information sharing path. With unsecure implementation this can reveal sensitive information. The purpose of the EMC testing is to make sure the device is not generating unwanted conducted or radiated emissions, that would leak sensitive information. The countermeasures on these aspects is called TEMPEST, which a must in cryptographic devices. Also injective emissions attacks shall be prevented.
> Reverse engineering
Reverse engineering methods are used to model PCB structures and schematics to understand how the system works. More understanding creates more attack interface too. Reverse engineering is commonly used also for software binaries, which contain sensitive intellectual property (IP), which can reveal the whole functionality, or even cryptographic keys and passwords, to compromise the security of the product completely. Therefore countermeasure are needed to mask logics and protect sensitive IP.
Side-channel analysis (SCA) evaluates whether a device leaks sensitive information through physical side channels such as power consumption, electromagnetic emissions, audio, temperature, or mechanical vibrations. It is widely used to assess the security of cryptographic implementations and determine whether secret keys can be recovered from repeated measurements.
Our testing includes methods such as TVLA, CPA, SPA, and DPA for both symmetric and asymmetric cryptography. Effective countermeasures are essential to prevent trace-based attacks and protect sensitive data.
Fault injection analysis evaluates how a system behaves under intentionally induced faults. By forcing microcontrollers, SoCs, or FPGAs into unexpected states, attackers may bypass secure boot, security checks, or hardware protection mechanisms.
We assess resistance against voltage, electromagnetic, and laser fault injection techniques, and implement countermeasures that strengthen resilience against both semi-invasive and invasive attacks.
Electromagnetic testing evaluates wireless communications and electromagnetic emissions that could expose sensitive information. It covers protocol implementation, modulation, encoding, encryption, and the analysis of conducted and radiated emissions.
We verify compliance with EMC requirements while identifying information leakage risks. For high-security products, TEMPEST countermeasures help prevent both passive monitoring and active electromagnetic injection attacks.
Reverse engineering reveals how hardware and software are designed and can expose valuable intellectual property or security weaknesses. PCB reconstruction, schematic analysis, and firmware extraction may uncover system functionality, cryptographic keys, or embedded credentials.
We assess resistance against reverse engineering and implement protection techniques that safeguard hardware logic, firmware, and other critical intellectual property.
Secure Production
Secure production transforms the designed product into fully functional product that can be delivered to the customer, for the most demanding conditions.
> PCB and PCBA
Printed circuit board (PCB) is the foundation for electronics, with a chosen stack-up of number of layers, copper thickness, substrate materials, impedance control, power delivery, signal delivery, heat delivery and attachment points. The first step for the outsourced PCBs is to do solder pasting, after it’s assembled with the defined bill-of-materials and the chosen assembly variant. Assembled PCB is then soldered with vapor phase or reflow oven, and the PCB assembly (PCBA) is ready for the quality inspection with visual and X-ray methods. The next step is to use nail test beds to run functional tests and verify that PCB works as planned.
> Sourcing
Sourcing of the components plays a vital role in managing supply chain security together with the counterfeit detection and obsolete management planning. Components must be in right time in the production line, creating an efficient manufacturing process. Sourcing experts do a constant risk analysis for lead times, component availability, end-of life reports, second sourcing and cost structure on the critical components.
> Assembly
Product assembly puts together assembled PCBs, enclosures, internal cables, connectors, mechanical supports and other auxiliary components to make a product complete. Secure, clean and ESD controlled facility is required in all assembly stages. The rigorous verification and validation actions from the individual PCBs to fully assembled product prove that product fulfills all regulatory, safety, security and functional requirements. The signed Certificate of Conformance is a written statement of this fulfillment.
> Crypto Provisioning
Products that handle highly secure or classified material, us typically unclassified until keyed. The product itself requires internal certificates, root-of-trust anchors, and encryption keys to manage the overall security. The keying process shall be controlled and secure. When the product is sent to customer and it’s keyed by the operator, the product reaches it’s highest security level. Cryptographic key management systems and dedicated key fill devices are used to generate and destroy the cryptographic key material, which must be handled securely for the whole lifecycle of the product.
Printed circuit boards (PCBs) form the foundation of every electronic system. Their design defines the layer stack, materials, signal integrity, power delivery, thermal performance, and mechanical integration.
After fabrication, PCBs are assembled, soldered, inspected using visual and X-ray methods, and functionally tested. The result is a verified PCB assembly (PCBA) ready for product integration.
Secure sourcing is essential for reliable manufacturing and supply chain resilience. It includes counterfeit detection, component lifecycle management, and ensuring critical parts are available when needed.
Our sourcing process continuously evaluates lead times, availability, end-of-life risks, second-source options, and cost to maintain a stable and efficient production flow.
Assembly brings together PCBAs, enclosures, cables, connectors, and mechanical components into a complete product. All work is performed in secure, clean, ESD-controlled environments to ensure quality and reliability.
Every product undergoes comprehensive verification and validation to meet functional, regulatory, safety, and security requirements. Compliance is documented with a signed Certificate of Conformance.
Security-critical products become fully operational only after secure cryptographic provisioning. During this process, certificates, root-of-trust anchors, and encryption keys are securely generated, installed, and managed.
From manufacturing through deployment, cryptographic key material is protected throughout its lifecycle using dedicated key management systems and secure key-loading devices.
