ASSURED INFORMATION SECURITY, INC. — Department of Defense STTR Phase I: HR001120S0019-20

ASSURED INFORMATION SECURITY, INC. — STTR Phase I award from Department of Defense.

Amount
$224,853
Agency
Department of Defense · Defense Advanced Research Projects Agency
Program / Phase
STTR · Phase I
Topic
HR001120S0019-20
Solicitation
HR001120S0019.T
NAICS
Place of performance
NY
Period
2021-02-03 → 2022-01-02

Description

Team AIS proposes tRustEd STORage dEvice (RESTORE), a secure microcontroller bootloader and operating system (OS) that will form the foundation of a next-generation secure USB removable storage device.  Our system will provide defense in depth through integration of several defensive techniques. Our system will achieve a secure measurement-based bootloader capability using a new trusted computing primitive called dominance. Our approach extends beyond typical concerns of firmware integrity by providing additional guarantees about firmware availability, even in the case that an adversary is able to completely replace the firmware with their own arbitrary code. We will leverage existing formally verified software components as the foundation for capabilities-based access control mechanism. The seL4 microkernel will be leveraged as the runtime environment for our developed code, while HACL  will be explored to implement critical functions provided by our OS. Our system will impose a minimal and configurable performance overhead that can be tuned to the specific security needs of a particular device deployment. Furthermore, our system will provide minimum integration requirements for existing microcontroller firmware through a minimal runtime interface consisting of two syscalls. This will make the RESTORE system applicable to a variety of device families such as network interface cards (NICs).