RAM LABORATORIES — Department of Defense SBIR Phase I: ABSTRACT: Data sources or services residing in tactical or enterprise environments may be

RAM LABORATORIES — SBIR Phase I award from Department of Defense.

Amount
$149,991
Agency
Department of Defense · Air Force
Program / Phase
SBIR · Phase I
Solicitation
2012.1
NAICS
Place of performance
CA
Period
2012-05-09

Description

ABSTRACT: Data sources or services residing in tactical or enterprise environments may be captured or compromised by an adversary for the purpose of attacking or disrupting armed forces, command and control, or business operations. As these networks are extended to accommodate mobile devices, external systems and guest users, there is a need for distributed form of trust assessment and remote authentication in order to ensure the trustworthiness of the new services being used to compose workflows. RAM Laboratories proposes to address this need by developing a Remote Attestation and Distributed Trust in Networks (RADTiN) solution that can be used to assess the trustworthiness of newly discovered services and data sources. The Phase I effort focuses on investigating the solution space for RADTiN by evaluating: the types of authentication and access control for handling distributed users, (2) techniques for delegation and reputation (trust) management processes for incorporating new sources/services that extend beyond access control lists, (3) trust metrics and protocols for evaluating and negotiating trust information, and (4) anti-tamper techniques for protecting trust credentials, security agents and protocols from adversarial threats. Additionally, this Phase I effort will evaluate the cost of implementing the most promising of these solutions. BENEFIT: RAM Laboratories will bring our commercialization expertise to bear on this effort, which will develop RADTiN, a tamper-proof remote attestation and distributed trust management solution for establishing trust in a multi-agent environment. RADTiN has the potential to fill a void that is critically lacking in the military and commercial trusted computing space. As systems fall under continual attack and subversion, their critical data (passwords, personal information, encryption keys) is subject to exfiltration and misuse in a manner that not only affects the system/owner in question, but potentially all nodes interacting with that device. Technologies are needed to not only attest to the trustworthiness of the system, but to also maintain the requisite tamper-proofing through deployment as close to bare metal as possible to ward off all adversary threats. The resulting solution can be employed in chipsets, software modules and operating systems for all areas of trusted and secure computing in the embedded computing space like mobile phones, trusted networking, and secure content management. The Chip Card and Security Segment is part of the overall semiconductor market. Key players in this market include Atmel, Broadcom, Infineon Technologies, and Intel among others. Additionally, the technology will be used to enable Digital Rights Management (DRM for solutions where vendor lock-out and anti-piracy technologies are especially needed to protect digital content (music, media, file-sharing). For instance, according to PRWeb, the market for DRM is expected to reach $2.5B by 2017. To take advantage of these immense opportunities to commercialize this technology, RAM Laboratories"strategy involves a three-pronged approach that addresses (1) licensing, (2) product sales, and (3) technical services. Each of these elements is an integral part of our corporate growth strategy. Our licensing approach entails making the Intellectual Property for our RADTiN protocols and distributed trust assessment algorithms available to semiconductor and microcontroller device manufactures for inclusion in their trusted computing products. Our product-based approach entails developing a value-added product that builds on existing vendor technologies. For instance our solution can be provided as a software solution that can store critical information in existing TPM chips or out-of-band processors. Another solution is to provide a RADTiN based product as a co-processor card based on the Freescale iMX31 Lightkit. In this particular case our solution will be tailored to our customer"s cost and security goals. Our service-based approach entails tailoring our solutions for our customers through technical service and integration agreements.