Structured Hardening Project

Specifications

The versioned technical documents that define the Structured Hardening Project standard.

SHP Specifications

The Structured Hardening Project is defined through versioned technical specifications.

The website explains the SHP model in accessible form.

The applicable specifications define its technical meaning.

Where explanatory website content and an authoritative specification differ, certification decisions must follow the applicable authoritative specification.

Specification structure

The SHP specification corpus separates different kinds of authority rather than treating every document as equivalent.

The corpus includes documents governing areas such as:

  • project and governance principles
  • tier mathematics
  • platform-specific mathematics
  • threat models
  • control catalogues
  • evidence
  • verification
  • certification decisions
  • certification trust
  • evaluation language
  • implementation architecture

The authority of a document depends on its defined role within the SHP specification hierarchy.

Platform specifications

Platform-specific documents define requirements that cannot safely be assumed from another platform.

A platform may require its own:

  • threat model
  • mathematical rules
  • control catalogues
  • applicability rules
  • verification behaviour
  • certification boundaries

Publication of a platform-related document does not, by itself, establish that a complete implementation or public certification service is available.

Versioning

Specifications are versioned.

A certification must be interpretable against the specification versions applicable when it was issued.

Later specification changes must not silently rewrite the historical meaning of an earlier certification.

Where a security-critical change requires different treatment, that treatment must be explicit rather than retroactively implied.

Amendments

Changes to SHP specifications are controlled.

Amendments must preserve document identity and version history and must distinguish material changes from minor corrections or clarifications.

Historical certification meaning must remain recoverable from the applicable versioned rules.

Certification authority

Specifications define what can qualify for certification.

They do not themselves issue certification.

Certification requires:

  1. an applicable supported certification target
  2. valid verification evidence
  3. satisfaction of the applicable certification decision rules
  4. issuance under SHP-controlled certification authority

The existence of a specification is therefore not equivalent to the existence of a certification service.

Public specification library

The public specification library will expose approved SHP documents with sufficient metadata to identify exactly what is being read.

Published specification records should identify, as applicable:

  • document title
  • document identifier
  • version
  • status
  • authority class
  • publication date
  • superseded version
  • cryptographic digest

The library must not present drafts, obsolete documents, and current authoritative specifications as though they have identical status.

Machine-verifiable publication

Where cryptographic digests or signatures are published for specifications, they must correspond to the actual published document.

Placeholder hashes, fingerprints, signatures, or identifiers must never be presented as trust information.

Current publication status

The website is currently being rebuilt around the SHP specification model.

The formal public document library will be populated only from documents whose publication status and metadata have been deliberately established.

Until then, the absence of a document from this page must not be interpreted as changing the authority or existence of the underlying SHP specification corpus.

The SHP Standard · Verification · Certification