Secure OPen source softwarE and hardwaRe Adaptable framework
Security of open-source solutions in the business interconnected market (especially in IoT where a single product may include components from various Tier 1 or OEM manufacturers) is hard to assure. OEM SW/HW developers that employ...
ver más
¿Tienes un proyecto y buscas un partner? Gracias a nuestro motor inteligente podemos recomendarte los mejores socios y ponerte en contacto con ellos. Te lo explicamos en este video
Proyectos interesantes
ORSHIN
Open-source ReSilient Hardware and software for Internet of...
4M€
Cerrado
SecIoT
Cybersecurity Threat Detection for Internet of Things Connec...
118K€
Cerrado
REWIRE
REWiring the ComposItional Security VeRification and Assura...
4M€
Cerrado
webinos
Secure Web OS Application Delivery Environment
14M€
Cerrado
YAKSHA
Cybersecurity Awareness and Knowledge Systemic High level Ap...
2M€
Cerrado
ANASTACIA
Advanced Networked Agents for Security and Trust Assessment...
5M€
Cerrado
Información proyecto SecOPERA
Duración del proyecto: 35 meses
Fecha Inicio: 2023-01-01
Fecha Fin: 2025-12-31
Líder del proyecto
POLYTECHNEIO KRITIS
No se ha especificado una descripción o un objeto social para esta compañía.
TRL
4-5
Presupuesto del proyecto
5M€
Fecha límite de participación
Sin fecha límite de participación.
Descripción del proyecto
Security of open-source solutions in the business interconnected market (especially in IoT where a single product may include components from various Tier 1 or OEM manufacturers) is hard to assure. OEM SW/HW developers that employ open-source solutions must assume that any component provided by 3rd parties needs to be reassessed for security as there is not holistic security auditing/testing process to cover the full production line. The plethora of open-source HW/SW solutions on devices with constrained resources and no trusted environments leads to a considerably expanded threat landscape. The restricted execution environment reduces bootstrapping new devices in an IoT network and deploying/patching them securely; and the full DevSecOps of connected device open-source HW/SW must be reformulated offering security guarantees on the usage of open-source solutions. SecOPERA will provide a one stop hub for complex OSS/OSH solutions offering to designers, implementers, operators and open-source HW/SW developers the means to analyse, assess, secure/harden and share open-source solutions as these are integrated in an overall complex product within a networked connected environment. SecOPERA provides a framework supporting the open source DevSecOps lifecycle that comprises (i) a decomposition and security audit/testing engine that analyses open source solutions (OSS/OSH) (ii) an adaptation engine that debloats OSS/OSH code to remove unrelated open-source code and reduce the code attack surface; and a security enhancement process to harden the OSS/OSH solution (iii) an updating/patching mechanism so that the SecOPERA open-source flows remain secure even if their open-source code starting points are vulnerable. On top of that, SecOPERA hub provides (iv) an open-source repository for secure modules that is used in the security enhancement mechanism of open-source solutions; and (v) an open-source repository of security hardened OSS/OSH solutions and their security guarantees.