ASSURED INFORMATION SECURITY, INC. — Department of Defense STTR Phase II: HR001120S0019-20

ASSURED INFORMATION SECURITY, INC. — STTR Phase II award from Department of Defense.

Amount
$1,999,990
Agency
Department of Defense · Defense Advanced Research Projects Agency
Program / Phase
STTR · Phase II
Topic
HR001120S0019-20
Solicitation
HR001120S0019.T
NAICS
Place of performance
NY
Period
2021-08-30 → 2025-03-08

Description

Team AIS proposes Phase II of trRustEd STORage dEvice (RESTORE), a high-assurance firmware architecture and update mechanism. RESTORE firmware will mitigate the risks associated with removable Universal Serial Bus (USB) mass storage devices caused by the lack of security protocols of existing USB microcontrollers (MCUs). RESTORE will perform this mitigation by composing several defensive techniques. Our firmware will achieve a secure measurement-based bootloader capability using a trusted computing primitive called dominance. While dominance is ideally suited for resource constrained MCUs, its existing instantiations share a common problem: establishing trust in the PC host used for the initial provisioning step. RESTORE Phase II will solve this problem by developing a trusted, x86-based I/O architecture using an existing micro-hypervisor and I/O kernel with formally verified properties. This I/O architecture will provide the owner of RESTORE devices with a trusted path over which USB transactions, such as those required by dominance provisioning, may occur. In addition to the trusted I/O architecture, Phase II will transition the proof-of-concept USB firmware and update mechanism developed under Phase I to isolated seL4 applications using the Component Architecture for microkernel-based Embedded Systems (CAmkES) framework. Team AIS will use the high-level abstractions provided by CAmkES to fully leverage the fine-grained access control afforded by seL4 capabilities while maximizing the portability of RESTORE firmware. In turn, Team AIS will use this portability to minimize the cost of applying the RESTORE solution to device types other than USB, such as solid-state drives and network interface cards. The wide applicability of the RESTORE implementation will play a key role in the successful transition of RESTORE to government and commercial deployments.