wolfSSL Inc. — Department of Defense STTR Phase I: A21C-T022

wolfSSL Inc. — STTR Phase I award from Department of Defense.

Amount
$77,040
Agency
Department of Defense · Army
Program / Phase
STTR · Phase I
Topic
A21C-T022
Solicitation
21.C
NAICS
Place of performance
WA
Period
2022-06-23 → 2022-12-20

Description

1.  Build and enable wolfBoot secure boot for the 5777m processor, including integration with the onboard HSM.  This will be one foundation that we will have in place for secure firmware updates on the neXtECU.  wolfBoot is OS agnostic, so if an OS is chosen for neXtECU, whether it be RTA-OS, OSEK, SafeRTOS, or something else, we will enable support for it.   Once enabled for the 5777m, wolfBoot will be delivered to VT for penetration and glitch testing.   2.  As a part of building and enabling wolfBoot, we will build and enable wolfCrypt FIPS, our  FIPS 140-2/3 validated cryptographic software library.  https://www.wolfssl.com/license/fips/. Given that neXtECU will run on US ARMY vehicles, the cryptographic primitives will need to be FIPS 140-2/3 tested.  In this early stage of the effort, we will do the software build and initial testing, but not engage in the full FIPS process.  That should be reserved for later in the neXtECU development cycle. 3.  We will also build and enable wolfSSL, which is an advanced TLS 1.3 software library that relies on wolfCrypt FIPS.  TLS 1.3 will be tested and benchmarked over CAN by VT.  TLS is the industry’s best and most vetted protocol for authentication and secure communication, and we have already enabled it on many different ECU’s for the likes of GM, Volkswagen, Ford, FCA, Aptiv, Veoneer, and others.  We can provide references upon request.  We are currently assuming that the CAN protocol is available on the prototype ECU. 4.  We will also port wolfSentry to the neXtECU.  wolfSentry is an IDPS for embedded systems.  We will create an initial set of basic rules to identify an intrusion, as well as an ability to notify the crew of a cyber attack.  This basic toolkit will be handed over to VT for extensions and testing, as the initial threat modeling that they do will be feeding back into the set up of wolfSentry. 5.  wolfSSH will be ported and tested and evaluated as an initial method for delivering secure firmware updates.  In the case that another method is chosen for firmware updates, then wolfSSH will serve as a backup to the chosen method.   6.  All of the above will undergo initial benchmark testing to determine performance characteristics and suitability.  VT will apply threat modeling and subsequent initial penetration testing. 7.  At the end of this project wolfSSL and VT will deliver a fully documented working cybersecurity prototype for the neXtECU, with initial penetration testing completed.  The prototype will include mitigations for all major attack vectors. 8.  We sincerely believe that we have a the best vetted, most advanced and most popular USA built cybersecurity solutions for ECU’s, and the track record to prove it.  Additionally, we are open source, come to the table with 24x7 support, and have the best cybersecurity engineering staff in the automotive industry.