Msb Associates — Department of Defense STTR Phase I: HR001120S0019-20

Msb Associates — STTR Phase I award from Department of Defense.

Phase I STTR feasibility signal

  • Phase I awards fund proof-of-concept work. For capture teams, they mark early interest from Department of Defense in a technical approach.
  • Watch for Phase II follow-ons from the same firm/topic family — that conversion path is where budgets and transition pressure rise.
  • Obligated amount $224,844. Cross-check similar awards in the same agency and technology tags for going-rate context.
  • Topic code HR001120S0019-20 links this award to a solicitation family — search the same topic stem for incumbents and recompete timing.

Informational capture context from public federal data — not legal or bid advice.

Amount
$224,844
Agency
Department of Defense · Defense Advanced Research Projects Agency
Program / Phase
STTR · Phase I
Topic
HR001120S0019-20
Solicitation
HR001120S0019.T
NAICS
Place of performance
CA
Period
2021-01-27 → 2021-12-26

Description

Memory sticks are a convenient mechanism for portable data storage and transfer. Unfortunately, the embedded microcontroller required to present raw flash as a USB peripheral exposes an attack surface that can enable privilege escalation on a host computer even in the presence of tamper-resistant device designs, data encryption, and host protections such as anti-virus software. We propose Twizzler, a novel operating system for secure embedded devices, as a means to secure memory sticks against these and other threats. Twizzler is a customizable, small footprint operating system designed for low-latency and high-bandwidth access to byte-addressable persistent memory, providing a flat privilege model with no superuser role. We intend to extend the current Twizzler code base to include: a system of cryptographically signed capabilities which form the basis for security contexts, a flexible and secure replacement for roles, integrate Twizzler's content-based, verified object names with the state-of-the-art in secure boot technology, and develop secure gated APIs as a fine-grained replacement for system calls and IPC. These extensions to Twizzler's 5000 line kernel (which is already amenable to formal verification) will ensure a system based upon least privilege, data integrity, and fine-grained isolation.