Phase II Amount
$1,432,310
Mission Assurance by Provisioning Assets Correctly with Hermetic Evidence (MAPACHE) is a proposed project to develop and demonstrate software tools that provision and automatically verify sensitive information assets during mission planning and execution. MAPACHE will demonstrate that software tooling, supply chain provenance analysis, and automatic checking protocols can significantly mitigate the risk of missing, mismatched, incorrectly generated, or supply-chain compromised information assets during provisioning. A secondary aim of MAPACHE is to reduce or eliminate reliance on manual asset provisioning and provide mission planners with an automated means of assuring asset readiness at large scales. The prototype of MAPACHE will include an asset manufacturing system to be specified by DARPA. Each asset created by this system will be paired with a Cryptographic Bill of Materials (CBOM) that specifies the underlying assets, algorithms, protocols and software used to create the asset. Each asset will additionally be augmented by a Software Bill of Materials (SBOM) manifest for each platform that handles the asset. The SBOM will be used to represent the provenance and supply chain properties of the asset. The MAPACHE tooling will additionally make these manifests available for operators to inspect and verify during the distribution and provisioning process. The second component of the MAPACHE system is a mission planning tool (MPT). The MPT is a graphical tool that catalogs the equipment in the mission planners possession, and identifies the information assets that are needed to operate this equipment. The MPT will provide a capability to visually connect mission-relevant equipment that will need to communicate during a mission, and update the information asset manifest accordingly. When the mission has been specified in the MPT, the mission planner can export the information asset manifest to assist in provisioning. Finally, the MAPACHE system will include an Asset Verification Tool (AVT) that will ingest the signed CBOM/SBOM manifests and the MPT information asset manifest. This will enable provisioners to automatically verify the functional correctness (e.g., that the assets can be loaded on to the target platforms and will communicate with required equipment) and health status (e.g., supply chain integrity and policy compliance) of their assets. If verification fails, the AVT will provide a report about which failures occurred for documentary and troubleshooting purposes. Together, the CBOM/SBOM manifests, MPT, and AVT will enable state of the art information asset provisioning for diverse equipment and complex policy requirements.