Loading…

Loading grant details…

Completed PROJECT GRANT Swedish Research Council

CEST - Confidential Evaluation of Software Trustworthiness

93.97M kr SEK

Funder Vinnova
Recipient Organization Ericsson Ab
Country Sweden
Start Date May 24, 2021
End Date May 24, 2023
Duration 730 days
Number of Grantees 1
Roles Principal Investigator
Data Source Swedish Research Council
Grant ID 2021-01690_Vinnova
Grant Description

Purpose and goal:

Due to increased softwarerization of critical infrastructures governments are issuing security regulations on software security assurance. Manufacturer of, e.g. telco equipment must disclose their proprietary software code to 3rd party evaluators. But proprietary software contains intellectual property and disclosing source code across jurisdictions increases the risk of piracy and zero-day attacks.

The project main goal was to research a solution that would allow the evaluation of software security and collection of assurance evidence without source code disclosure. Expected results and effects:

The project has designed a service that allows software vendors to submit their encrypted proprietary software to a secure platform, where the software is confidentially evaluated, and only evaluation results are exposed to authorized 3rd party evaluators. The source code is never disclosed. Two emerging technologies make the approach feasible: confidential computing and AI-powered software analysis tools.

The project has implemented a proof-of-concept that shows the feasibility of the approach for Telco security assurance, but the approach applies to other industry sectors. Approach and implementation:

The project lasted 2-years May 2021 May 2023 with 4 partners: atsec, Ericsson, Hyker and RISE. Ericsson took the roles of project management and technical coordination. The work was divided into 4 working packages (WPs) and each WP consisted of several tasks.

For each task, one partner was assigned to drive it according to the partner skills and competence. The major bulk of work was on the development and implementation of the proof-of-concept (PoC) that took extra time and resources to complete. The PoC is deployed as a Service for interested parties.

All Grantees

Ericsson Ab

Advertisement
Apply for grants with GrantFunds
Advertisement
Browse Grants on GrantFunds
Interested in applying for this grant?

Complete our application form to express your interest and we'll guide you through the process.

Apply for This Grant