CUREX

CUREX addressed comprehensively the protection of the confidentiality and integrity of health data by producing a novel, flexible and scalable situational awareness-oriented platform. It allowed healthcare providers to assess the realistic cybersecurity and privacy risks they were exposed to and suggest mathematically optimal strategies for addressing these risks with safeguards tailored specifically for each business case and application. CUREX was GDPR compliant by design and aimed to develop one of the first blockchain platforms for risk assessment management under the GDPR. At its core, a decentralized architecture enhanced with a private blockchain infrastructure ensured the integrity of the risk assessment process and of all data transactions that occurred between the diverse range of stakeholders involved. Crucially, CUREX expanded beyond technical measures and placed emphasis also on improving cyber hygiene through training and raising awareness activities for a healthcare institution’s personnel. Its validation focused on the highly challenging condition of (cross-border) health data exchange, spanning patient cross-border mobility, remote healthcare, and data exchange for research.

ASCLEPIOS

The vision of ASCLEPIOS was to maximize and fortify the trust of users on cloud-based healthcare services by developing mechanisms for protecting both corporate and personal sensitive data. ASCLEPIOS utilized several modern cryptographic approaches to build a cloud-based eHealth framework that protected users’ privacy and prevented both internal and external attacks. ASCLEPIOS offered to users the ability to verify the integrity of their medical devices prior to using them, whilst receiving certain guarantees about the trustworthiness of their cloud service provider. Furthermore, ASCLEPIOS offered a novel solution through which healthcare practitioners and medical researchers were able to calculate statistics on medical data in a privacy-preserving way. A list of activities aiming to raise security awareness within the healthcare industry were also foreseen to be organized by the project. The project’s results were showcased through three real-life, near production quality demonstrators provided by ASCLEPIOS healthcare partners, involving three leading European hospitals.

PUZZLE

PUZZLE implemented a highly usable cybersecurity, privacy and data protection management marketplace targeted at SMEs&MEs that enabled them to monitor, forecast, assess and manage their cyber risks through targeted cybersecurity services, increase their cybersecurity awareness through the efficient heterogeneous information processing, the establishment of knowledge sharing with other SMEs&MEs and extract insights based on advanced analytics. The PUZZLE tracked the relationships among the cyber assets of each SME&ME, considering the available network, compute and storage infrastructure and used them to efficiently calculate individual, cumulative and propagated risks, as well as recommend and apply mitigation actions. PUZZLE also supported vulnerabilities and threats assessment in a collaborative manner based on the homogenization of data provided by the SMEs&MEs. Data was collected by resource handling and monitoring agents applied over Cloud/Edge Computing, IoT and network infrastructure. Such data was enriched with data provided in relevant open repositories. SMEs&MEs data sharing took place through blockchain-based technologies for secure data management. Based on the calculated risks and the provided graph topology, the application of resilient defensive strategies was recommended, considering the type of infrastructure used by the SME&ME. Automated defensive strategies deployment mechanisms were also made available, reducing a lot the complexity and the burden for the deployment of the provided services by cybersecurity managers in SMEs&MEs. Special emphasis was given on the usability and the rise of competitiveness of the PUZZLE Marketplace, by designing solutions that could be easily on-boarded by external cybersecurity providers and could be seamlessly adopted by the end-users taking into account their preferences.

REWIRE

The main objective of REWIRE was to provide a holistic framework for continuous security assessment and management throughout the entire lifecycle of IoT devices under the zero-trust concept, while at the same time adhered to the security-by-design principle. REWIRE ambition was realised through the achievement of the following project-wide objectives.

OB1: Continuous security assessment and management of IoT devices throughout the entire lifecycle (bootstrapping, commissioning, operation, upgrade) under zero-trust conception

OB2: Security-by-design through formally verified open-source software and open standard hardware designs for attack surface minimisation

OB3: Runtime verification of IoT trustworthiness through cryptographically verifiable security proofs and efficient attestation

OB4: Cyber Security situational awareness in heterogeneous IoT environments through auditable security patch management and misbehavior detection

OB5: Trust-aware continuous authentication and authorization for the secure communication and identity management in IoT ecosystems

OB6: Simulation, Validation & Evaluation of REWIRE Framework in the field of Smart Cities, Smart Satellites and Smart Automotive

OB7: Communication, exploitation and standardization strategy for adoption of REWIRE outcomes

FutureTPM

The goal of FutureTPM was to design a Quantum-Resistant (QR) Trusted Platform Module (TPM) by designing and developing QR algorithms suitable for inclusion in a TPM. The algorithm design was accompanied with implementation and performance evaluation, as well as formal security analysis in the full range of TPM environments: i.e. hardware, software and virtualization environments.

HORSE

6G technologies, benefitting from softwarisation, Gb/s speed and sub-THz communications paradigms, open up opportunities for developing new and innovative network management strategies while navigating the evolution toward disaggregation, new software-based paradigms in architecting and operating future connectivity platforms, and embracing features of computing, automation and smartness, trust, privacy and security. Supported by this technology evolution, as the vision of new, smart and innovative capabilities is becoming a reality, superb user experience is expected even in presence of mobility and resource volatility. However, the fundamentally new and unknown features of advanced, disaggregated, virtualized and multi-vendor 6G based infrastructures, challenge the security and resilience design to the next level, by managing the unknown, complex and highly versatile infrastructures as they evolve. Indeed, the future deployment of 6G networks is inextricably connected with an integration of diverse hardware elements and infrastructures, thus leading not only to a highly heterogeneous environment, but also to functions and features that cannot be anticipated at the time of design. The vision of HORSE in this complex scenario, was to deal with the technology solutions, and system evaluation not yet foreseen, towards an omnipresent, smart and secure network service provisioning in the future network-of-networks landscape. To this end, HORSE proposed a novel human-centric, open-source, green, sustainable, coordinated provisioning and protection evolutionary platform, which could inclusively yet seamlessly combine advancements in several domains, as they get added to the system (e.g., predictive threats detection, proactive business-wise threats and breaches mitigation actions, programmable networking, semantic communications, Network Function Virtualisation (NFV), intent-based networking, AI-based techniques, cross-layer management of physical layer features, etc.).

ENTRUST

Aligned with the guidelines of the Cybersecurity Act and the existing guidance on cybersecurity for medical devices, ENTRUST envisioned a Trust Management Architecture intended to dynamically and holistically manage the lifecycle of connected medical devices, strengthening trust and privacy in the entire medical ecosystem. Even from the proposal stage, ENTRUST had identified gaps and necessary revisions of the current guidance (e.g. absence of post-market conformity and certification, real-time surveillance and corrective mechanisms). Towards that ENTRUST leveraged a series of breakthrough solutions to enhance assurance without limiting the applicability of connected medical devices by enclosing to them cybersecurity features. The project introduced a novel remote attestation mechanism to ensure the device’s correct operation at runtime regardless of its computational power; it was efficient enough to run in also resource-constrained real-time systems such as the medical devices. This was accompanied by dynamic trust assessment models capable of identifying the Required Level of Trustworthiness (RTL) per device and function (service) that were then verified through a new breed of efficient, attestation mechanisms (deployed and executed during runtime). This also enabled us to be aligned with the existing standards on defining appropriate Protection profiles per device (especially considering the heterogeneous types of medical devices provided by different vendors with different requirements) including Targets of Validation Properties attested during runtime. The motivation behind ENTRUST was to ensure end-to-end trust management of medical devices including formally verified trust models, risk assessment process, secure lifecycle procedures, security policies, technical recommendations, and the first-ever real-time Conformity Certificates to safeguard connected medical devices.

ASSURED

ASSURED’s vision was to introduce a ground-breaking policy-driven, formally verified, runtime assurance framework in the complex Cyber Physical Systems (CPS) domain. ASSURED leveraged and enhanced runtime property-based attestation and verification techniques to allow intelligent (unverified) controllers to perform within a predetermined envelope of acceptable behaviour, and a risk management approach to extend this to a larger SoS. ASSURED elaborated over the coordination of deployed TEE agents in horizontal scope, encompassing numerous technologies applicable to everything from edge devices to gateways in the cloud. Such technologies DICE for binding devices to firmware/software, trusted execution environments, formal modelling of protocols and software processes, software attestation, blockchain technology for distributed verification of transactions between system elements and control-flow attestation techniques for enhancing the operational correctness of such devices.

CONNECT

CONNECT addressed the convergence of security and safety in CCAM by assessing dynamic trust relationships and defining a trust reasoning framework based on which involved entities could establish trust for cooperatively executing safety-critical functions. This enabled both a) cyber-secure data sharing between data sources in the CCAM ecosystem that had no or insufficient pre-existing trust relationship, and b) outsourcing tasks to the MEC and cloud in a trustworthy way. Beyond the needs of functional safety, trustworthiness management should be included in CCAM’s security functionality solution for verifying trustworthiness of transmitting stations and infrastructure. CONNECT built upon and expanded the Zero Trust concept to tackle the issue of how to bootstrap vertical trust from the application, the execution environment and device hardware from the vehicle up to MEC and cloud environments. This included measuring the system when instantiating network functions and determining the integrity and origin of software. Trusted Execution Environments (TEEs), as sw- or hw-based security elements, were essential to establish a verifiable chain of trust throughout the entire application stack of the host vehicle, as well as protecting data in transit, at rest and in use. By coupling the Zero Trust security principle with the need of “Never Trust, Always Verify”, CONNECT bootstrapped vertical trust for all users, devices and systems in the CCAM ecosystem by enabling continuous authorization and authentication prior to be granted access to data or resources. Through TEE-enabled “Chip-to-Cloud”” assurances and verifiable chain of trust, CONNECT reached its full potential: not only did it mitigate risks stemming from the Zero Trust CCAM environment but also ensured resilience. This could make CONNECT the cornerstone of future smart transportation as it would usher new levels of safety and connectivity and bring vehicles even close to autonomy.

eFORT

eFORT approach aimed to enable the further upgrading of the energy grid without affecting the security of supply and increasing their reliability and resiliency against extreme weather events, man-made hazards and equipment failures. The project put in place a set of solutions at the cyber and physical layers for detecting, preventing and mitigating vulnerabilities and threats. Among them, an interoperable Intelligent Platform set a common foundation for grid characterization and vulnerability overseeing, as well as gathered information from smart grid components and applied heavy-duty algorithms, whereas Asset Management developments strengthened grid infrastructure robustness, which was empowered by the addressed Digital Technologies. All these elements were validated in relevant environments coming from 4 demo cases covering the whole grid value chain: (i) a transmission network (The Netherlands); (ii) a remote distribution grid (Italy); (iii) a digital substation in Ukraine; and (iv) a micro-grid in Spain.