REAL-TIME INNOVATIONS, INC. — Department of Defense STTR Phase I: ABSTRACT: Modern critical systems present a heterogeneous footprint with different domain
REAL-TIME INNOVATIONS, INC. — STTR Phase I award from Department of Defense.
- Amount
- $99,978
- Agency
- Department of Defense · Air Force
- Program / Phase
- STTR · Phase I
- Solicitation
- 2011.B
- NAICS
- —
- Place of performance
- CA
- Period
- 2012-04-18
Description
ABSTRACT: Modern critical systems present a heterogeneous footprint with different domains, operating systems, devices, and network protocols. Often, such systems rely on information originating from remote embedded devices, which run on commercially available platforms that cannot be assumed to be trusted. To address this problem, RTI and the Battelle propose a real-time remote attestation approach. We propose to use measurement tools for determining the integrity of software running on remote devices. Using virtualization, we will separate the target device"s OS and software from the measurement tools such that the integrity of the measurements cannot be compromised. We will use TPM hardware as the root of trust for the software measurements. The attestation information will be securely communicated using the security-enhanced OMG Data Distribution Service standard. At the end of Phase I, RTI and Battelle will provide the design of an architecture that can assess the trust posture of a remote embedded device, by measuring its software integrity and communicating the result to a local verifier using DDS as the attestation transport. Moreover, given the intrinsic characteristics of DDS, we will also provide capabilities for determining misconfigured local and remote devices. Finally, we will build a prototype to demonstrate the proposed concepts. BENEFIT: This STTR directly addresses the shortcomings in current approaches to maintaining an end-to-end trusted path across a heterogeneous distributed system. It will provide the capability to establish the attestation of code executing on remote platforms, automatically check for mis-configurations, provide isolation between software components, and maintain a resilient channel to communicate information security across the network. This will result in much greater confidence in the integrity of information received from remote devices that are often spread across wide geographic areas and organizational domains. The technology developed by RTI during this STTR will benefit programs that recognize the security vulnerabilities in their existing embedded applications. We already have interest in this from several of our existing DoD Prime contractor customers. Over the long-term, we foresee strong sales to our Navy, Army, USAF, and Intelligence Community (IC) programs that need a more comprehensive distributed security infrastructure. The technology also has significant commercial potential. Embedded applications such as financial systems, equity trading platforms, industrial control systems, heath care, and critical infrastructure such as power distribution are all potential users of this technology.