SECMATION LLC — Department of Defense STTR Phase II: A21C-T022
SECMATION LLC — STTR Phase II award from Department of Defense.
- Amount
- $1,199,345
- Agency
- Department of Defense · Army
- Program / Phase
- STTR · Phase II
- Topic
- A21C-T022
- Solicitation
- 21.C
- NAICS
- —
- Place of performance
- NC
- Period
- 2023-08-31 → 2025-08-30
Description
Cybersecurity of modern automotive systems is a growing concern. Modern vehicles continue to rapidly grow in functionality to support autonomous driving, electrification, and advanced user interfaces. Cyber-attacks on commercial vehicles could result in significant safety, privacy, and availability issues. Military vehicles have additional concerns. They must function in contested environments targeted by advanced cyber threats, be modified over their life cycle with additional subsystems from multiple vendors, and be easily maintained to ensure readiness. To prepare for these challenges, the Army Ground Vehicle Systems Center (GVSC) is developing the neXtECU to act as a primary component of military vehicle electrical systems. The neXtECU incorporates a Hardware Security Module (HSM) which can be configured for use as a Root of Trust (RoT). A RoT can provide system security protections and assured cryptographic functions to support many different vehicle applications. The RoT can support secure functions such as: working with the bootloader to authenticate system software ensuring a boot to a known secure state, protecting confidentiality of cryptographic keys, providing accelerated cryptographic functions for secure protocols, and cryptographic signing providing integrity protection of vehicle information including audit records/security logs. The neXtECU program objective is to design a full-featured Vehicle Root of Trust (VRoT) for an Electronic Control Unit (ECU) of a vehicle. The VRoT provides a secure execution environment for critical vehicle control software by authenticating software loaded to the ECU prior to permitting an application to run. The VRoT allows software to be digitally signed prior to being loaded to the ECU, allowing the authenticity of the software to be verified at a later date. Additionally, the VRoT calculation includes a secure hash signed using the private Elliptic-Curve Cryptography (ECC) key. This allows the contents of the ECU to be verified by calculating the hash and using the public ECC key to verify the VRoT during boot to ensure no unauthorized changes have been made to the SW. If unauthorized changes are detected, the VRoT can, based on customer preference, prevent the applications from booting, allow the applications to boot with a warning supplied to the user, or fall back to a second instance of storage containing a known-good configuration. It is implemented on an Infineon AURIX TC399 processor with a built-in Hardware Security Module (HSM) with hardware acceleration. This includes providing multiple cryptographic algorithms including several variations of AES, SHA, RSA, and ECDSA, along with random number generation. The goal of the proposed Phase II program is to complete the implementation of the VRoT in conjunction with a bootloader, and work with Army GVSC to integrate the VRoT with their ECU applications.