scieee AI-readable full text Open interactive document viewer

ELASTIC D6.2: Initial communication, dissemination, standardisation and exploitation activities

Vasic, Jelena; Gunn, Lachlan; Holler, Jan

Abstract

This deliverable (D6.2) summarises the implementation of ELASTIC’s communication, dissemination, standardisation, and exploitation strategies during the initial reporting period (M1–M18). Building on the framework defined in D6.1, the report captures how the consortium has promoted awareness of the project, engaged with stakeholders across different communities, contributed to standardisation activities, and explored pathways for exploitation. The deliverable presents a consolidated view of achievements to date and outlines priorities for the next project phase. The purpose is to ensure alignment with the objectives of Work Package 6 and to provide a clear baseline for the continuation of activities through to the end of the project.

Full text

Horizon Europe Framework Programme HORIZON JU Research and Innovation Action Reliable Services and Smart Security Efficient, portabLe And Secure orchesTration for reliable servICes D6.2: Initial communication, dissemination, standardisation and exploitation activities Abstract: This deliverable (D6.2) summarises the implementation of ELASTIC’s communication, dissemination, standardisation, and exploitation strategies during the initial reporting period (M1–M18). Building on the framework defined in D6.1, the report captures how the consortium has promoted awareness of the project, engaged with stakeholders across different communities, contributed to standardisation activities, and explored pathways for exploitation. The deliverable presents a consolidated view of achievements to date and outlines priorities for the next project phase. The purpose is to ensure alignment with the objectives of Work Package 6 and to provide a clear baseline for the continuation of activities through to the end of the project. Contractual Date of Delivery 31/08/2025 Actual Date of Delivery 31/08/2025 Deliverable Security Class Public Editor Jelena Vasic (ZEN), Lachlan Gunn (AAL), Jan Holler (ERS) Contributors All ELASTIC partners Internal Reviewers Brent Mc Credie, Volker Breuer (THD) Despina Kopanaki (TUC) ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 2 - August 31, 2025 The ELASTIC Consortium Part . No. Participant organisation name Participan t Short Name Role Countr y 1 POLYTECHNEIO KRITIS TUC Coordinator EL 2 ERICSSON AB ERS Principal Contractor SE 3 OY L M ERICSSON AB ERF Principal Contractor FI 4 TELEFONICA INNOVACION DIGITAL SL TID Principal Contractor ES 5 THALES SIX GTS FRANCE SAS THS Principal Contractor FR 6 THALES DIS FRANCE SAS THD Principal Contractor FR 7 INTERUNIVERSITAIR MICROELECTRONICA CENTRUM IME Principal Contractor BE 8 ULTRAVIOLET CONSULT DOO UVC Principal Contractor RS 9 AALTO KORKEAKOULUSAATIO SR AAL Principal Contractor FI 10 LUNDS UNIVERSITET LUN Principal Contractor SE 11 ABSTRACT MACHINES SAS AMA Principal Contractor FR 12 PRIVREDNO DRUSTVO ZENTRIX LAB DRUSTVO SA OGRANICENOM ODGOVORNOSCU PANCEVO ZEN Principal Contractor RS 13 POLITECNICO DI TORINO POLITO Principal Contractor IT ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 3 - August 31, 2025 Document Revisions & Quality Assurance Internal Reviewers 1. Brent Mc Credie, Volker Breuer, THD 2. Despina Kopanaki, TUC Revisions Version Date By Overview 1.0 31/08/2025 TUC Comments and approval from the PC 0.8 30/08/2025 TUC Quality check 0.7 30/08/2025 THD, TUC Approval from the IRs 0.6 30/08/2025 ZEN 2nd draft 0.5 29/08/2025 THD, TUC Comments on the 1st draft 0.4 25/08/2025 ZEN First draft 0.3 22/08/2025 ALL partners Input received 0.2 23/04/2025 TUC, THS Comments on the TOC 0.1 23/04/2925 ZEN TOC Disclaimer The work described in this document has been conducted within the ELASTIC project. This project has received funding from the Smart Networks and Services Joint Undertaking (SNS JU) under the European Union’s Horizon Europe research and innovation programme under Grant Agreement No 101139067. This document does not reflect the opinion of the European Union, and the European Union is not responsible for any use that might be made of the information contained therein. This document contains information that is proprietary to the ELASTIC Consortium partners. Neither this document nor the information contained herein shall be used, duplicated, or communicated by any means to any third party, in whole or in parts, except with prior written consent of the ELASTIC Consortium. The quality of this deliverable was improved with the assistance of digital tools; all content was reviewed and approved by the authors. ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 4 - August 31, 2025 Table of Contents LIST OF TABLES 6 LIST OF FIGURES 7 LIST OF ABBREVIATIONS 8 EXECUTIVE SUMMARY 10 1 INTRODUCTION 12 1.1 PURPOSE AND SCOPE OF THE DOCUMENT 12 1.2 RELATION TO WORK PACKAGES, DELIVERABLES AND ACTIVITIES 12 1.3 CONTRIBUTION TO WP6 AND PROJECT OBJECTIVES 13 1.4 STRUCTURE OF THE DOCUMENT 14 2 COMMUNICATION AND DISSEMINATION ACTIVITIES 15 2.1 OVERVIEW OF ACTIVITIES PERFORMED 15 2.2 OVERVIEW OF ELASTIC DISSEMINATION AND COMMUNICATION PLAN 16 2.3 SCIENTIFIC PUBLICATIONS AND OPEN ACCESS CONTRIBUTIONS 16 2.4 EVENTS, CONFERENCES, AND WEBINARS 18 2.5 PROJECT WEBSITE, SOCIAL MEDIA CHANNELS AND VIDEO 21 2.5.1 Project Video 28 2.6 NEWSLETTERS, PRESS RELEASES AND CAMPAIGNS 29 2.6.1 Newsletters 30 2.6.2 Press Releases 33 2.6.3 Campaigns 33 2.7 PRINTED AND PROMOTIONAL MATERIALS 42 2.8 COLLABORATION WITH EU PROJECTS AND SNS JU PARTICIPATION 48 2.9 VISUAL IDENTITY AND COMMUNICATION ASSETS 53 3 ECOSYSTEM ENGAGEMENT AND STAKEHOLDER INVOLVEMENT 55 3.1 STAKEHOLDER MAPPING AND TARGET GROUPS 55 3.2 FOCUS GROUP ACTIVITIES 57 3.2.1 Members of the ELASTIC External Expert Advisory Board 58 3.3 ENGAGEMENT WITH POLICYMAKERS, ACADEMIA AND INDUSTRY 58 3.4 COLLABORATION WITH INNOVATION ECOSYSTEMS 59 4 STANDARDISATION AND OPEN-SOURCE CONTRIBUTIONS 62 4.1 STANDARDISATION STRATEGY AND OBJECTIVES 62 4.1.1 Cluster Formation 63 4.1.2 Standardisation Activity Development 63 4.1.3 Whitepaper on Standards Gaps 63 4.2 PARTICIPATION IN STANDARDS DEVELOPING ORGANISATIONS (SDOS) 64 4.3 OPEN-SOURCE COMMUNITY ENGAGEMENT 66 4.4 OUTLOOK 67 5 EXPLOITATION ACTIVITIES 69 5.1 PLAN AND METHODOLOGY 69 5.2 EXPLOITATION FINDINGS 74 5.2.1 Commercial and intellectual property 74 5.2.2 Technological exploitation 75 5.2.3 Business exploitation and the ELASTIC ecosystem 75 5.2.3.1 Target users and ecosystem perspectives 76 5.2.3.2 Value proposition – the pains and gains 78 5.3 ELASTIC POTENTIAL KEY EXPLOITABLE RESULTS 82 5.3.1 KER #1: 6G-embedded IoT data fabric 83 5.3.2 KER #2: Privacy-preserving and secure on premise to public cloud computing platform 84 ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 5 - August 31, 2025 5.3.3 KER #3: Secure Wasm-native cloud-to-edge workload orchestrator (Propeller Orchestrator) 86 5.3.4 KER #4: WebAssembly Platform for Distributed Trusted Systems 88 5.3.5 KER #5: Confidential Computing, Security and Privacy Toolkit 89 5.4 FUTURE EXPLOITATION PATHWAYS 90 6 KPIS AND MONITORING 92 7 CONCLUSION AND NEXT STEPS 97 8 ANNEX I – EXPLOITATION ANALYSIS OF ELASTIC INDIVIDUAL COMPONENTS 98 ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 6 - August 31, 2025 List of Tables Table 1: ELASTIC Scientific Publications ............................................................................................ 17 Table 2: ELASTIC Zenodo Repository ................................................................................................. 18 Table 3: Detailed Overview of ELASTIC Events and Contributions .................................................... 19 Table 4: ELASTIC statistics about social media ................................................................................... 25 Table 5: Template for Exploitable Results Analysis.............................................................................. 71 Table 6: ELASTIC Potential Key Exploitable Results .......................................................................... 83 Table 7: Dissemination & Communication KPIs Table ........................................................................ 92 Table 8: Federated Learning as a Service (FLaaS) - TID ...................................................................... 98 Table 9: Wasm-operator - IMEC ........................................................................................................... 99 Table 10: Light-weight Security Orchestrator for Edge Devices - THS .............................................. 100 Table 11: Federated Learning Toolbox - ZEN ..................................................................................... 102 Table 12: TEE Software Management Agent - UVC .......................................................................... 103 Table 13: Reliable enclave migration protocols - AAL ....................................................................... 104 Table 14: Propeller orchestrator - AMA .............................................................................................. 106 Table 15: Data protection at-rest at the edge with TEE solution - THS .............................................. 107 Table 16: WasmHAL-Trust: Automation tooling for confidential computing environments - LUN . 109 Table 17: WASI Security - IMEC ........................................................................................................ 110 Table 18: Automatic MAC profiles for Wasm runtime containers - LUN .......................................... 111 Table 19: WasmHAL Hardware SDK, interfaces, and runtime extensions for securely connecting Wasm applications to hardware across platforms - IMEC .............................................................................. 113 Table 20: Static eBPF code security Analyser - POLITO ................................................................... 114 Table 21: Static analysis of interaction between Wasm modules - AAL ............................................ 116 Table 22: Accelerated microservices interconnection - POLITO ........................................................ 118 Table 23: eBPF distributed state synchronisation - POLITO .............................................................. 119 Table 24: NETTO - A tool to measure the cost of the Linux network stack in real-time - POLITO .. 121 Table 25: Hardware-based cryptography module - TUC ..................................................................... 123 Table 26: Artificial Intelligence Intrusion Detection/Prevention System - TUC ................................ 124 Table 27: Mobility attack robust IoT resource allocation model - LUN ............................................. 126 Table 28: Observability framework for serverless workloads - ERF .................................................. 127 Table 29: Remote Attestations platform - THD ................................................................................... 129 Table 30: Key Broker Service - THD .................................................................................................. 131 Table 31: Multi-platform attestation component - ERF ....................................................................... 133 Table 32: Light-weight Attribute-based Access Control (ABAC) solution - THS .............................. 134 Table 33: WASI flexibly-defined capabilities - AAL .......................................................................... 135 ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 7 - August 31, 2025 List of Figures Figure 1. ELASTIC project website - EU & 6GSNS Funding statement .............................................. 23 Figure 2. ELASTIC project website....................................................................................................... 23 Figure 3. ELASTIC Project - Website Mockup ..................................................................................... 24 Figure 4. ELASTIC Project LinkedIn Account ..................................................................................... 26 Figure 5. ELASTIC Project X Account ................................................................................................. 26 Figure 6. ELASTIC Project Instagram Account .................................................................................... 27 Figure 7. ELASTIC Project Bluesky Account ....................................................................................... 27 Figure 8. ELASTIC Project YouTube Channel ..................................................................................... 28 Figure 9. ELASTIC Project YouTube Video ......................................................................................... 29 Figure 10. ELASTIC Project - LinkedIn Newsletter ............................................................................. 30 Figure 11. ELASTIC Project - AI & Security Webinar Newsletter ...................................................... 31 Figure 12. ELASTIC Project - Third Issue of Newsletter ..................................................................... 32 Figure 13. ELASTIC Project - Meet the Partners Campaign - TUC ..................................................... 34 Figure 14. ELASTIC Project - Meet the Partners Campaign - Telefonica ............................................ 35 Figure 15. ELASTIC Project - Meet the Partners Campaign - IMEC ................................................... 35 Figure 16. ELASTIC Project - Meet the Partners Campaign - ZEN ..................................................... 36 Figure 17. ELASTIC Project - Women in STEAM Campaign: Despina Kopanaki .............................. 37 Figure 18. ELASTIC Project - Women in STEAM Campaign: Dhouha Ayed ..................................... 38 Figure 19. ELASTIC Project - Women in STEAM Campaign: Jelena Vasic ....................................... 39 Figure 20. ELASTIC Project - Did You Know? .................................................................................... 40 Figure 21. ELASTIC Project - Publication (LinkedIn Banner) ............................................................. 41 Figure 22. ELASTIC Project - Publication (Instagram Banner) ............................................................ 42 Figure 23. ELASTIC Project Brochure .................................................................................................. 44 Figure 24. ELASTIC Project Rollup ...................................................................................................... 45 Figure 25. ELASTIC Project Poster....................................................................................................... 46 Figure 26. ELASTIC Project Notebook and Brochures......................................................................... 47 Figure 27. ELASTIC Project luggage tags ............................................................................................ 48 Figure 28. ELASTIC Project T-shirt Mockup ....................................................................................... 48 Figure 29. AI & Security Webinar Booklet ........................................................................................... 50 Figure 30. AI & SECURITY Webinar Banner ...................................................................................... 51 Figure 31. AI & SECURITY Webinar Speakers Banner ....................................................................... 51 Figure 32. ELASTIC Project logo variations ......................................................................................... 54 Figure 33. ELASTIC Project PowerPoint Presentation Slides Template .............................................. 54 Figure 34. ELASTIC Project: Stakeholder Mapping ............................................................................. 57 Figure 35. ELASTIC Project – External Expert Advisory Board - kick-off Meeting ........................... 58 Figure 36. ELASTIC Exploitation Roadmap ......................................................................................... 70 Figure 37. A simplistic generic value chain of relevance to ELASTIC................................................. 76 Figure 38. The value proposition canvas ............................................................................................... 79 ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 8 - August 31, 2025 List of Abbreviations 3GPP 3rd Generation Partnership Project ABAC Attribute-Based Access Control AI Artificial Intelligence BMC Business Model Canvases CACAO Collaborative Automated Course of Action CCC Confidential Computing Consortium CNCF Cloud Native Computing Foundation CT Core Network and Terminals (3GPP Working Group) EC European Commission EEAB External Expert Advisory Board ENISA European Union Agency for Cybersecurity ETSI European Telecommunications Standards Institute FaaS Function-as-Service GDPR General Data Protection Regulation HRB Horizon Results Booster IoT Internet of Things IPR Intellectual Property Rights KER Key Exploitable Result KPI Key Performance Indicator LLVM Low Level Virtual Machine M Month NFV Network Functions Virtualisation OSF OpenStack Foundation OSS Open-Source Software PC Project Coordinator R&D Research & Development SA Service and System Aspects (3GPP Working Group) SDO Standards Developing Organisation SEO Search Engine Optimisation SIG Special Interest Group SME Small and Medium-sized Enterprise SOC Security Operations Centre SNS JU Smart Networks and Services Joint Undertaking ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 9 - August 31, 2025 SSP Safe Stack Protection (Wasm security feature) STEAM Science, Technology, Engineering, Arts, and Mathematics TEE Trusted Execution Environment TOC Table of Contents TRL Technology Readiness Level VPC Value Proposition Canvas WASI WebAssembly System Interface Wasm WebAssembly W3C World Wide Web Consortium WG Working Group WP Work Package ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 16 - August 31, 2025 partner contributions. These efforts helped ensuring consistent messaging and broadened the reach of the project across different audience groups. ZEN coordinated these activities to ensure coherence in messaging and alignment with the overall communication strategy. Partners contributed by promoting project outcomes through their institutional and professional networks, preparing and delivering presentations, and supporting content creation across various dissemination formats. A set of templates was developed to maintain consistency in visual identity and messaging, covering blog posts, presentations, social media content, event reports, and newsletters. Partner contributions were gathered through structured requests, ensuring broad representation and timely updates aligned with project milestones. A shared tracking system was used to monitor progress and document partner inputs, social media activities, publication outputs, and participation in events. This allowed for regular assessment against communication and dissemination KPIs and supported adjustments in response to feedback and new opportunities. Overall, the plan remained dynamic and adaptable, providing a flexible framework that supported strong engagement and maintained the relevance of the project within the wider research and innovation community. 2.2 Overview of ELASTIC Dissemination and Communication Plan A comprehensive dissemination and communication plan was designed at the start of ELASTIC to effectively promote the project’s vision, showcase technical developments, and engage diverse audiences throughout its lifetime. Detailed in D6.1, this plan outlined specific objectives, defined priority stakeholder groups, and set ambitious outreach targets to maximise project visibility and impact. The plan combined traditional and dynamic channels, including the project website, social media platforms, newsletters, press materials, scientific publications, and active participation in events. It also emphasised the development of a strong visual identity through the project logo, templates, and printed materials such as brochures and posters. During the reporting period, the overall framework remained consistent with what was originally defined. Adjustments were introduced to respond to emerging opportunities and evolving project needs — for example, expanding participation in external events, refining key messages to reflect technical progress, and creating additional visual assets to support targeted campaigns. Under the guidance of ZEN, partners aligned their contributions to maintain consistency in communication materials and to reinforce the overall objectives of the project. All partners actively contributed by preparing content, sharing updates through their networks, and supporting promotional activities, which helped strengthen connections with key stakeholder groups and the wider community. This coordinated, flexible approach enabled the consortium to maintain a strong presence in both scientific and industry circles, support community building, and prepare the foundation for wider uptake and future exploitation of project outcomes. 2.3 Scientific Publications and Open Access Contributions Scientific publications are a key component of ELASTIC’s strategy to disseminate research results, contribute to ongoing technical discussions, and engage with the wider academic and ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 17 - August 31, 2025 technical community. By sharing findings through peer-reviewed articles and conference papers, the project highlights its technical advancements, fosters collaboration, and supports the development of secure and efficient 6G orchestration solutions. During the reporting period, partners focused on presenting early technical results, methodological innovations, and initial insights from demonstrator activities. A total of 11 conference publications were produced, covering topics such as Trusted Execution Environments (TEEs), secure edge orchestration, advanced Linux networking, and WebAssembly for cyber-physical systems. Additional manuscripts are in preparation and planned for submission to high-impact journals and future conferences, further supporting the project's scientific outreach objectives. All partners contributed to publication activities by preparing content, reviewing drafts, and presenting results at international conferences and workshops. These contributions ensured that research outputs reflected the breadth of expertise across the consortium and showcased the collaborative nature of the project. ZEN coordinated the tracking of scientific outputs to maintain alignment with the dissemination plan defined in D6.1 and to monitor progress against KPIs. In parallel, TUC managed the ELASTIC Zenodo community 2 , which serves as the main open access repository for project outputs. As of M18, a total of 19 records, including publications, public deliverables, promotional materials, and presentation slides, have been uploaded to the ELASTIC Zenodo community. These materials have collectively generated 2,875 downloads and 616 total views, supporting open science practices and ensuring broad accessibility of the project’s results. A summary of the scientific publications produced during this period is presented in Table 1, while Table 2 provides an overview of the activity within the ELASTIC Zenodo community. Table 1: ELASTIC Scientific Publications Author Publication Title Conference Name Link Federico Parola, Shixiong Qi, Anvaya B. Narappa, K. K. Ramakrishnan, Fulvio Risso SURE: Secure Unikernels Make Serverless Computing Rapid and Efficient 15th ACM Symposium on Cloud Computing (SoCC'24) ZENODO Florent Foucaud, Esther Galby, Liana Khazaliya, Shaohua Li, Fionn Mc Inerney, Roohani Sharma, Prafullkumar Tale Metric Dimension and Geodetic Set Parameterized by Vertex Cover 42nd International Symposium on Theoretical Aspects of Computer Science (STACS 2025) ZENODO Ioannis Lamprou, Alexander Shevtsov, Despoina Antonakaki, Polyvios Pratikakis, Sotiris Ioannidis Exploring Crisis-Driven Social Media Patterns: A Twitter Dataset of Usage During the Russo-Ukrainian War 6th International Conference on Advances in Social Networks Analysis and Mining (ASONAM 2024) ZENODO Michiel Van Kenhove, Maximilian Seidler, Friedrich Vandenberghe, Warre Dujardin, Wouter Hennen, Arne Vogel, Merlijn Sebrechts, Tom Goethals, Filip De Turck, Bruno Volckaert Cyber-physical WebAssembly: Secure Hardware Interfaces and Pluggable Drivers 38th IEEE/IFIP Symposium on Network Operations and Management (NOMS 2025) ZENODO Quentin Michaud, Yohan Pipereau, Olivier Levillain, Dhouha Ayed Robust Stack Smashing Protection for WebAssembly IEEE Future Networks World Forum 2024 (FNWF 2024) ZENODO Quentin Michaud, Yohan Pipereau, Securing Stack Smashing 19th Workshop on Programming ZENODO 2 “ELASTIC – Efficient, portabLe And Secure orchesTration for reliable servICes,” zenodo.org. https://zenodo.org/communities/elastic/records?q=&l=list&p=1&s=10&sort=newest [accessed Aug. 28, 2025]. ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 18 - August 31, 2025 Olivier Levillain, Dhouha Ayed Protection in WebAssembly Applications Languages and Analysis for Security (PLAS 2024) Robert Ganian, Fionn Mc Inerney, Dimitra Tsigkari Parameterized Complexity of Caching in Networks 39th AAAI Conference on Artificial Intelligence (AAAI 2025) ZENODO Robert Ganian, Liana Khazaliya, Fionn Mc Inerney, Mathis Rocton The Computational Complexity of Positive NonClashing Teaching in Graphs 13th International Conference on Learning Representations (ICLR 2025) ZENODO Stavros Eleftherakis, Timothy Otim, Giuseppe Santaromita, Almudena Diaz Zayas, Domenico Giustiniano, Nicolas Kourtellis Demystifying Privacy in 5G Stand Alone Networks 30th Annual International Conference On Mobile Computing And Networking (ACM MobiCom 2024) ZENODO Syafiq al Atiiq, Christian Gehrmann, Yacha Yuan, Jacob Sternby AutoML in the Face of Adversity: Securing Mobility Predictions in NWDAF The 9th International Conference on Fog and Mobile Edge Computing (FMEC 2024) ZENODO Rosario Rizza, Riccardo Sisto, Fulvio Valenza Design and implementation of a tool to improve error reporting for eBPF code 2025 IEEE International Conference on Cyber Security and Resilience (CSR 2025) ZENODO Table 2: ELASTIC Zenodo Repository Number of Uploads Total Downloads Total Views 19 2,875 616 2.4 Events, Conferences, and Webinars Active participation in events, conferences, and webinars is a key element of ELASTIC’s strategy to promote its technical advancements, engage with diverse stakeholder groups, and strengthen connections within the research and innovation community. These activities support knowledge exchange, enhance project visibility, and foster collaboration across both academic and industry environments. During the reporting period, ELASTIC partners participated in a total of 17 conferences, presenting research outcomes, technical innovations, and project visions to a broad audience. Contributions included presentations at major events such as EuCNC & 6G Summit 2025, FIRST Conference 2024, NetSoft 2024, Netdev 0x18, and other specialised conferences focused on Internet of Things (IoT), cybersecurity, WebAssembly, and edge computing. These venues provided valuable opportunities to showcase ELASTIC’s progress, discuss technical challenges, and receive feedback from both the academic and industry communities. In addition to conferences, partners were involved in 12 meetings and panel sessions, which included technical workshops, clustering activities, and invited expert discussions. Highlights include participation in the SNS Call 2 project introduction webinar, various WebAssembly subgroup meetings, discussions hosted by Carnegie Mellon University, and panels at EdgeSys 2024, the Open RAN Global Forum, and the SPATIAL Final Event. These engagements facilitated deeper technical exchanges, allowed partners to position ELASTIC within strategic discussions, and supported alignment with broader European research efforts. The project also co-organised and delivered a dedicated webinar on AI & Security, in collaboration with the Predict-6G, RIGOUROUS, CONFIDENTIAL6G, and HARPOCRATES projects, with additional support from FAITH, CUSTODES, and 6GCloud. The webinar focused on secure and privacy-preserving AI approaches for future ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 19 - August 31, 2025 network architectures and attracted over 125 participants from diverse sectors, reflecting strong community interest. On the ELASTIC side, Merlijn Sebrechts (IMEC) contributed with a presentation titled “Resilient Cyber-Physical Devices with WebAssembly Sandboxing” during Session 3: Security & Privacy in Next-Gen Network Orchestration. The event fostered new opportunities for cross-project collaboration, knowledge exchange, and future joint initiatives within the 6G research ecosystem. The recording is available on the AI & Security YouTube channel 3 and all presentations are accessible via Zenodo 4 . ERF presented the ELASTIC demonstrator In-network Data Fabric at the workshop "Data Integration for Next-Generation IoT", part of the 14th International Conference on the Internet of Things (IoT 2024) in Oulu, Finland. The workshop addressed data integration challenges in diverse IoT ecosystems, and provided a valuable opportunity to showcase ELASTIC’s contributions to simplifying in-network data processing and harmonisation. Event participation and contributions were managed directly by individual partners, who identified relevant opportunities, prepared presentations, and represented ELASTIC in various forums. ZEN supported these efforts by maintaining overall tracking, providing guidance on visual identity, and ensuring coherence with the overarching dissemination strategy. Collectively, these engagements played an essential role in positioning ELASTIC within leading scientific and industrial discussions, enhancing its visibility, and reinforcing its relevance in the evolving 6G and edge computing landscape. They also contributed to building a foundation for future collaboration, stakeholder engagement, and the eventual exploitation of project outcomes. A detailed overview of all conferences, meetings, panels, workshops, and webinars attended or organised by ELASTIC partners during the reporting period is presented in Table 3. This table includes information on the involved partners and speakers, event names, types, dates and locations, contributions or presentation topics, and related links. By consolidating this information, the table provides a clear record of the consortium’s extensive engagement efforts and illustrates the broad reach and visibility achieved across both scientific and industry communities. Table 3: Detailed Overview of ELASTIC Events and Contributions No Partners & Speaker Event name Type Date & Location Title/Contribution Link 1 LUN (Christian Gehrmann) Dutch Cybersecurity Delegation Meeting May 2024, Lund, Sweden Presentation of Lund University research including ELASTIC Website 2 TUC (Sotiris Ioannidis) SNS Call 2 Introduction Webinar Webinar March 2024, Virtual Presentation of ELASTIC project overview Website 3 IMEC (Merlijn Sebrechts) WASI-USB Meeting Meeting April 2024, Virtual Presentation of wasi-usb standard of WasmHAL Link 4 IMEC (Merlijn Sebrechts) WASI-I2C Meeting Meeting May 2024, Virtual Presentation of wasi-I2C standard of WasmHAL Link 5 TUC, UVC, AMA EuCNC & 6G Summit 2024 Conference June 2024, Antwerp, Participation in conference Website 3 “AI & SECURITY Webinar: Exploring the Future of Secure AI in …”, YouTube. https://www.youtube.com/watch?v=-QHpswMEOKc [accessed Aug. 28, 2025]. 4 “AI & Security Webinar – Presentations,” zenodo.org. https://zenodo.org/records/16779302 [accessed Aug. 28, 2025]. ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 20 - August 31, 2025 Belgium 6 TUC (Manos Athanatos) FIRST Conference 2024 Conference June 2024, Fukuoka, Japan Participation and discussions on cybersecurity automation Website 7 TID (Nicolas Kourtellis) SETN 2024 & ReAI 2024 Conference September 2024, Athens, Greece Presentation on Federated Learning and Responsible AI Website 8 ERF (Ari Keränen, Rajat Kandoi) IRTF T2TRG & Hackathon Hackathon May 2024, Paris, France Interim meeting and IoT security hackathon presenting ELASTIC concepts Website 9 ERF (Ari Keränen) IoT 2024 Conference Conference November 2024, Oulu, Finland Keynote presentation on 6G and IoT Data Fabric Link 10 ERF (Rajat Kandoi) IoT 2024 Workshop Workshop November 2024, Oulu, Finland Workshop on data integration for IoT Link 11 IMEC (Michiel Van Kenhove) WASI-SG Preprint Meeting Meeting October 2024, Virtual Presentation of cyber-physical WebAssembly preprint and WACE 2025 workshop promotion Website 12 IMEC (Merlijn Sebrechts) WebAssembly research center discussion series: Cyberphysical WebAssembly - Carnegy Mellon University Meeting November 2024, Virtual Discussion on cyber-physical WebAssembly standardisation 13 AMA, UVC (Drasko Draskovic, Dusan Borovcanin) WasmCon 2024 (Confidential Computing) Conference November 2024, Salt Lake City, USA Presentation on protecting Wasm workloads with TEEs Link 14 IMEC (Merlijn Sebrechts, Michiel Van Kenhove) WasmCon 2024 (Cyber-physical WebAssembly) Conference November 2024, Salt Lake City, USA Presentation on cyber-physical WebAssembly Website 15 THS (Quentin Michaud) PLAS24 (CCS 24) Conference October 2024, Salt Lake City, USA Presentation on securing stack smashing protection in WebAssembly Link 16 THS (Dhouha Ayed) IEEE FNWF 2024 Conference October 2024, Dubai Presentation on ELASTIC and security for future networks Link 17 THS (Dhouha Ayed) CSNET 2024 Conference December 2024, Paris, France Keynote on AI-native 6G network security and ELASTIC Link 18 THS (Dhouha Ayed) 6G-IA Working Group Presentation Collaboratio n/Meeting December 2024, Virtual Presentation of ELASTIC to 6G-IA group 19 TID (Nicolas Kourtellis) EdgeSys 2024 Panel Panel April 2024, Athens, Greece Panel on security and privacy in Federated Learning Link 20 TID (Nicolas Kourtellis) Open RAN Global Forum Panel Panel September 2024, Online Panel on automation and AInative 6G networks Link 21 TID (Nicolas Kourtellis) SPATIAL Final Event Panel Panel July 2024, Delft, Netherlands Panel on AI career opportunities and ELASTIC perspectives Link 22 POLITO NetSoft 2024 Conference June 2024, St. Louis, USA Presentation on Linux network stack monitoring (NETTO Website ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 21 - August 31, 2025 component) 23 POLITO Netdev 0x18 Conference July 2024, Santa Clara, USA Participation and presentation on low-level Linux networking Link 24 IMEC (Merlijn Sebrechts) SIG-Embedded Meeting Meeting March 2025, Virtual Presentation of wasi-gpio standard Link 25 IMEC (Merlijn Sebrechts) WASI Subgroup Meeting Meeting March 2025, Virtual Presentation of wasi-gpio standard Link 26 IMEC (Merlijn Sebrechts) Drupal Dev Days 2025 Conference April 2025, Leuven, Belgium Keynote: 'WebAssembly Beyond the Browser' Link 27 IMEC (Merlijn Sebrechts, Bruno Volckaert) Cybersec Europe 2025 Conference May 2025, Brussels, Belgium ELASTIC showcase at Ghent University booth Website 28 TUC (Prof. Sotiris Ioannidis, Gregory Chrysos) 2025 CyberHOT Week Summer School May 2025, Chania, Greece ELASTIC sponsored the event, ensuring strong project visibility. A project banner was prominently displayed, and dissemination materials were distributed to participants, raising awareness of ELASTIC’s objectives and outcomes among the summer school community. Website 29 IMEC (Merlijn Sebrechts), ERF (Jimmy Kjällman, Wentao Xie) and AAL (Lachlan Gunn, students) Secure Systems Demo Day Conference June 2025, Helsinki, Finland ELASTIC research showcase to students and industry professionals. ERF presented the multi-platform attestation component as a poster, and AAL organised the event and also presented their ELASTIC results as posters/demos. Link 30 POLITO (Rosario Rizza) 2025 IEEE International Conference on Cyber Security and Resilience (CSR 2025) Conference August 2025, Chania, Greece POLITO participated in the CSR 2025, where they presented the paper “Design and implementation of a tool to improve error reporting for eBPF code.” Website 2.5 Project Website, Social Media Channels and Video The ELASTIC website (https://elasticproject.eu/) serves as the primary online hub for sharing project information, promoting outcomes, and engaging with stakeholders. It is designed to present the project's objectives, research activities, use cases, consortium members, and the support received from the European Union and 6GSNS. Through its clear structure and userfriendly design, the website supports the project's communication objectives and enhances overall visibility, as illustrated in Figure 2 and Figure 3. The site includes dedicated sections on Research & Innovation, highlighting core scientific and technical activities and their practical applications. The Experimentation section is further divided into two subpages focusing on Demonstrator 1 and Demonstrator 2, which showcase key use cases and technological validations. A regularly updated "News & Updates" area features articles, press releases, event announcements, and highlights of project milestones. Additionally, a knowledge hub provides access to all public deliverables, scientific ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 22 - August 31, 2025 publications, and a media library containing brochures, posters, project presentations, and the AI & Security booklet. Technically, the website is mobile-friendly, optimised for fast loading, and fully accessible. It is GDPR compliant and designed with integrated search engine optimisation (SEO) practices to improve online reach. A newsletter subscription feature allows interested visitors to stay informed about recent progress and upcoming activities. The website is also fully integrated with all ELASTIC social media accounts, ensuring seamless redirection and consistent promotion across channels. As of the current reporting period, the website has recorded over 1.95K unique visitors and has published more than 49 news and update items, reflecting steady engagement and interest from both the scientific community and the general public. The website’s structure (site map) is outlined below: ● Homepage ○ Project Overview ○ Project Objectives ○ Research & Innovation ○ Demonstrators ○ Partners logos ○ Subscription Form ● About the Project ○ Project Overview ○ Concept ○ Impact ○ Work Packages ○ Partners ○ ELASTIC External Expert Advisory Board Members ● Research & Innovation ● Experimentation ○ Demonstrator 1 ○ Demonstrator 2 ● Knowledge Hub ○ Deliverables ○ Publications ○ Media ● News ○ News & Updates ○ Events ● Collaboration ● Contact In line with European Commission communication guidelines, the website explicitly acknowledges the support provided by the European Union and the Smart Networks and Services Joint Undertaking (SNS JU). As shown in Figure 1, the site prominently features the EU emblem, the SNS JU logo (displayed according to official brand guidelines), and the funding statement: ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 23 - August 31, 2025 “Views and opinions expressed are however those of the author(s) only and do not necessarily reflect those of the European Union or the European Commission. Neither the European Union nor the granting authority can be held responsible for them.” This acknowledgment is also systematically included across other communication materials, including presentations, brochures, and posters. The mock-up version of the website design is also presented in Figure 3, while Figure 2 provides an overview of the website homepage as currently implemented. Figure 1. ELASTIC project website - EU & 6GSNS Funding statement Figure 2. ELASTIC project website ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 24 - August 31, 2025 Figure 3. ELASTIC Project - Website Mockup Complementing the website, ELASTIC maintains an active presence across multiple social media platforms, including LinkedIn, X (formerly Twitter), Instagram, BlueSky, and YouTube. The combined community has grown to over 580 followers, and posts have generated more than 42,237 impressions in the last 18 months. These platforms are strategically used to amplify project announcements, share event highlights, promote publications and deliverables, and reinforce key messages to wider audiences. LinkedIn (Figure 4) serves as a professional network hub, allowing ELASTIC to showcase publications, present key results, announce events, and facilitate connections among research and industry stakeholders. It supports knowledge exchange, encourages collaborative opportunities, and provides a trusted space for sharing insights and engaging in professional discussions. X (Twitter) (Figure 5) functions as a dynamic micro-blogging platform, enabling timely promotion of findings, live event updates, and active participation in broader public and policy discussions through the use of strategic hashtags. It is particularly effective for rapidly amplifying news and engaging with journalists, EU community channels, and technical audiences. Instagram (Figure 6) complements these efforts by providing a more visual approach to storytelling. It helps present highlights from events, visual summaries of results, and behindthe-scenes glimpses into project activities, thereby broadening reach to audiences who prefer visual and accessible content. BlueSky (Figure 7), as a newer decentralised platform, offers additional opportunities to reach technical audiences and innovation communities. It supports concise, real-time updates and contributes to expanding the project's online presence beyond traditional social media ecosystems. ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 25 - August 31, 2025 YouTube (Figure 8) has been added as an additional channel to further expand outreach and support the dissemination of video content. Currently, the channel hosts the project’s general overview video, providing a concise and accessible introduction to ELASTIC’s objectives and vision. Future video materials may include demonstrations, technical highlights, and other promotional content to further engage audiences. The project also actively engages developer communities and technical networks through these channels and partner-associated networks, reinforcing its presence among technology innovators and practitioners. All social media activities are carefully planned and coordinated to ensure alignment with the overall communication strategy and the project's visual identity. The current statistics (Table 4) reflect steady growth and sustained community interest, confirming the importance and effectiveness of these channels in supporting ELASTIC’s dissemination objectives. LinkedIn is the primary dissemination hub, with 415 followers, 37,400 impressions, and 48 posts, clearly demonstrating its strength in reaching professional and industry stakeholders. X (Twitter) has attracted 68 followers and generated nearly 4,837 impressions across 38 posts, providing effective real-time visibility and engagement with EU and policy audiences despite a smaller community. Instagram, with 33 followers, 29 posts, and an average reach of 926 per post, shows strong potential for growth among visually oriented audiences. BlueSky, though newly established, has already gained 27 followers with 8 updates, positioning ELASTIC within emerging decentralised platforms. Finally, YouTube counts 37 subscribers, with its first video (the project overview) reaching 114 views; as more content such as demonstrations, technical highlights, and promotional clips is added, this channel is expected to expand significantly. The channels can be accessed at the following addresses: • LinkedIn: https://www.linkedin.com/company/elastic-project/ • X (Twitter): https://x.com/ElasticProject_ • Instagram: https://www.instagram.com/elastic_project/ • YouTube: https://www.youtube.com/@elastic_project • BlueSky: https://bsky.app/profile/elasticproject.bsky.social Table 4: ELASTIC statistics about social media Channel Followers Impressions Number of Posts 415 37,400 48 68 4,837 38 33 926/Reach 29 27 N/A 8 37 subscribers 114 1 video ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 32 - August 31, 2025 The most recent (third) newsletter 9 was also shared through the email mailing list and covered updates from July 2024 to May 2025. It provided a comprehensive summary of recent technical progress, key events, publications, and ongoing activities, supporting sustained engagement and keeping the community informed about ELASTIC’s evolving impact. A visual extract of this newsletter is presented in Figure 12. Figure 12. ELASTIC Project - Third Issue of Newsletter 9 “ELASTIC Newsletter – July 2024 to May 2025,” elasticproject.eu. https://elasticproject.eu/wpcontent/uploads/2025/06/ELASTIC-Newsletter-July-24-May-25-1.pdf [accessed Aug. 28, 2025]. ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 33 - August 31, 2025 All newsletters are designed to present concise, visually engaging content, including highlights of technical advances, partner contributions, event participation, and upcoming opportunities for involvement. They play a central role in maintaining continuous contact with stakeholders and reinforcing the project's visibility within the research and innovation ecosystem. Looking ahead, additional newsletters are planned for the coming reporting period, ensuring that updates on project milestones, technical progress, and opportunities for collaboration continue to reach a wide audience. This regular flow of newsletters will help sustain engagement, broaden outreach, and support the long-term visibility of ELASTIC. 2.6.2 Press Releases To date, ELASTIC has issued two press releases to announce key project milestones and strengthen outreach to a broad audience, including the research community, industry stakeholders, and the general public. The first press release was prepared by ZEN and focused on introducing the project’s objectives, initial activities, and overall vision for advancing secure, efficient, and privacypreserving orchestration technologies in 6G networks. The second press release was prepared by TUC and highlighted the project’s progress, upcoming technical demonstrations, and its role in shaping future 6G research and innovation priorities. Both press releases were published on the project website and are available for download as PDF documents, ensuring transparency and easy access for stakeholders and interested audiences. These press releases play an important role in raising the project’s profile, creating early visibility for technical results, and reinforcing ELASTIC’s contribution to the wider European 6G research landscape. Links: • First press release - ELASTIC Project Embarks on Advancing 6G Network Service Orchestration • Second press release - ELASTIC Project Celebrates a Successful First Year of Advancing Secure and Efficient Service Delivery for 6G Infrastructures Looking ahead, additional press releases are planned to coincide with upcoming milestones, such as technical demonstrations, major events, and the publication of significant project results. These future releases will continue to build awareness, broaden stakeholder engagement, and provide regular updates on ELASTIC’s role within the European 6G ecosystem. 2.6.3 Campaigns In addition to newsletters and press releases, ELASTIC has designed and executed several targeted communication campaigns to further increase visibility, foster community engagement, and highlight key messages and project outcomes. The "Meet the Partners" campaign introduced individual consortium members, showcasing their roles, expertise, and contributions to ELASTIC. This campaign helped humanise the project, strengthen connections with external audiences, and highlight the strong collaborative foundation within the consortium. ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 34 - August 31, 2025 Selected posts from this campaign are illustrated in Figure 13–Figure 16, with the corresponding links: ● Meet Our Partner: Technical University of Crete 10 ● Meet our Partner: Telefónica Innovación Digital 11 ● Meet our Partner: IMEC 12 ● Meet the partner: ZENTRIX LAB 13 Figure 13. ELASTIC Project - Meet the Partners Campaign - TUC 10 https://elasticproject.eu/meet-our-partner-technical-university-of-crete/ 11 https://elasticproject.eu/meet-our-partner-telefonica-innovacion-digital/ 12 https://elasticproject.eu/meet-our-partner-imec/ 13 https://elasticproject.eu/meet-the-partner-zentrix-lab/ ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 35 - August 31, 2025 Figure 14. ELASTIC Project - Meet the Partners Campaign - Telefonica Figure 15. ELASTIC Project - Meet the Partners Campaign - IMEC ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 36 - August 31, 2025 Figure 16. ELASTIC Project - Meet the Partners Campaign - ZEN The "Women in STEAM" campaign aimed to promote and celebrate the contributions of all women standing in front of the project, including researchers, engineers, project managers, communication leads, and other key contributors. By highlighting the diverse perspectives and expertise of women working across science, technology, engineering, arts, and mathematics (STEAM), as well as in essential coordination and support roles. The campaign reinforced ELASTIC’s commitment to gender equality and diversity within research and innovation environments. Selected posts from this campaign are illustrated in Figure 17–Figure 19, with the corresponding links: ● Women Driving ELASTIC: Despina Kopanaki on Leadership and Diversity 14 ● Women Driving ELASTIC: Dhouha Ayed on Innovation and Security in 6G 15 ● Women Driving ELASTIC: Jelena Vasic on Communication, Creativity, and Impact 16 14 https://elasticproject.eu/women-driving-elastic-despina-kopanaki-on-leadership-and-diversity/ 15 https://elasticproject.eu/women-driving-elastic-dhouha-ayed-on-innovation-and-security-in-6g/ 16 https://elasticproject.eu/women-driving-elastic-jelena-vasic-on-communication-creativity-and-impact/ ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 37 - August 31, 2025 Figure 17. ELASTIC Project - Women in STEAM Campaign: Despina Kopanaki ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 38 - August 31, 2025 Figure 18. ELASTIC Project - Women in STEAM Campaign: Dhouha Ayed ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 39 - August 31, 2025 Figure 19. ELASTIC Project - Women in STEAM Campaign: Jelena Vasic The “Did You Know?" campaign 17 focused on sharing interesting facts and insights related to ELASTIC’s technical focus areas, such as secure orchestration, privacy-preserving technologies, and advanced networking solutions for 6G. These posts helped engage the broader community by breaking down complex concepts into accessible messages and fostering curiosity about the project’s work. 17 “Did You Know? " campaign,” LinkedIn. https://www.linkedin.com/feed/update/urn:li:activity:7237042910611812354/ [accessed Aug. 28, 2025]. ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 40 - August 31, 2025 Figure 20. ELASTIC Project - Did You Know? Finally, a dedicated campaign was launched to promote conference papers published by the project. This campaign aimed to increase the visibility of ELASTIC’s scientific contributions presented at international conferences and encourage stakeholders to explore and share these results within their networks. By highlighting key research findings and technical advances, the campaign supported the project’s goal of engaging the broader research and innovation community. Links to selected posts: ● AutoML in the Face of Adversity: Strategies for Mobility Predictions in NWDAF 18 ● Demystifying Privacy in 5G Stand Alone Networks – New Research Publication 19 ● SURE: Secure Unikernels Make Serverless Computing Rapid and Efficient – New Research Publication 20 ● New Publication: Robust Stack Smashing Protection for WebAssembly 21 ● New Publication: Securing Stack Smashing Protection in WebAssembly Applications 22 (Figure 21) ● New Publication: Exploring Crisis-Driven Social Media Patterns: A Twitter Dataset of Usage During the Russo-Ukrainian War 23 18 https://elasticproject.eu/automl-in-the-face-of-adversity-strategies-for-mobility-predictions-in-nwdaf/ 19 https://elasticproject.eu/demystifying-privacy-in-5g-stand-alone-networks-new-research-publication/ 20 https://elasticproject.eu/sure-secure-unikernels-make-serverless-computing-rapid-and-efficient-new-research-publication/ 21 https://elasticproject.eu/new-publication-robust-stack-smashing-protection-for-webassembly/ 22 https://elasticproject.eu/new-publication-securing-stack-smashing-protection-in-webassembly-applications/ 23 https://elasticproject.eu/new-publication-exploring-crisis-driven-social-media-patterns-a-twitter-dataset-of-usage-duringthe-russo-ukrainian-war/ ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 41 - August 31, 2025 Figure 21. ELASTIC Project - Publication (LinkedIn Banner) ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 48 - August 31, 2025 Figure 27. ELASTIC Project luggage tags Figure 28. ELASTIC Project T-shirt Mockup 2.8 Collaboration with EU Projects and SNS JU Participation ELASTIC actively engages in collaboration and clustering activities with other EU-funded projects and maintains strong ties with the SNS JU community. These efforts aim to increase project visibility, promote knowledge exchange, and strengthen alignment with broader 6G research and innovation objectives. ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 49 - August 31, 2025 The project has collaborated closely with CONFIDENTIAL6G 24 , HARPOCRATES 25 , RIGOUROUS 26 , and PREDICT-6G 27 . A key example of this joint work was the organisation of the "AI & Security" webinar, held with the support of FAITH, CUSTODES, and 6G-Cloud. This event provided an important platform for discussing cross-cutting topics, exchanging technical insights, and reaching wider audiences across research and policy communities. The recording of the webinar has been made publicly available on the dedicated YouTube channel for the AI & Security initiative 28 while all presentations are accessible via the ELASTIC Zenodo community 29 . Promotional materials created to support the webinar (such as banners, social media visuals and online version of the booklet 30 ) were actively used to promote the event across ELASTIC’s communication channels and partner networks. Figure 29–Figure 31 present selected pages from the AI & Security booklet, the webinar banner, and the speakers’ banner, respectively, highlighting the campaign’s design and visibility. The AI & Security Webinar attracted 125 participants, representing a wide range of stakeholders, including leading research institutions, major industry players, innovative SMEs, and public bodies. The event gathered participants from across Europe and beyond, with representation from Asia, North America, and the Middle East. This diversity highlights the broad relevance of AI and security in the context of 6G, as well as ELASTIC’s role in fostering cross-sector dialogue. The strong presence of SNS JU projects and partners further underlined the webinar’s contribution to community building and collaboration within the 6G ecosystem. 24 CONFIDENTIAL6G – Confidential Computing for Secure 6G Cloud and Edge (GA No. 101096435), https://confidential6g.eu/ [accessed Aug. 28, 2025]. 25 HARPOCRATES – Holistic Approach for Providing Spatial Privacy Guarantees in Large-scale Systems (GA No. 101069535), https://www.harpocrates-project.eu/ [accessed Aug. 28, 2025] 26 RIGOUROUS – Rigorous Secure and Resilient 6G Systems (GA No. 101095933), https://rigourous.eu/ [accessed Aug. 28, 2025] 27 PREDICT-6G – AI-driven Predictive Orchestration for 6G (GA No. 101095890), https://www.predict-6g.eu/ [accessed Aug. 28, 2025] 28 “AI & Security Webinar: Exploring the Future of Secure AI in …”, YouTube. https://www.youtube.com/watch?v=-QHpswMEOKc [accessed Aug. 28, 2025]. 29 “AI & Security Webinar – Presentations,” Zenodo, DOI: 10.5281/zenodo.16779302. https://zenodo.org/records/16779302 [accessed Aug. 28, 2025]. 30 “AI & Security Webinar – Online Booklet,” Zenodo, DOI: 10.5281/zenodo.15222163. https://zenodo.org/records/15222163 [accessed Aug. 28, 2025]. ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 50 - August 31, 2025 Figure 29. AI & Security Webinar Booklet ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 51 - August 31, 2025 Figure 30. AI & SECURITY Webinar Banner Figure 31. AI & SECURITY Webinar Speakers Banner On the SNS JU side, ELASTIC has participated actively in community-building activities, most notably through its presence at the EuCNC & 6G Summit 2025, held in Poznań, Poland from ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 52 - August 31, 2025 3–6 June 31 . The project was represented at a joint booth (#12) together with the RIGOUROUS and CONFIDENTIAL6G projects, thereby reinforcing cooperation within the SNS JU portfolio. This collaborative setup increased overall project visibility, facilitated direct engagement with event participants, and promoted collective achievements and shared research priorities. Over the course of the 3.5-day exhibition, the booth attracted more than 80 visitors, including researchers, industry representatives, and policy stakeholders. ELASTIC showcased two highly interactive demonstrations: • Ericsson IoT Data Fabric, presenting semantic-based data access, in-network processing using WebAssembly (Wasm), and early security features built on IETF technologies; • IMEC WasmHAL, illustrating secure hardware access in sandboxed environments, complemented by a live Pac-Man game controlled through a WebAssembly-based USB driver. These demos highlighted the innovative role of WebAssembly as a central enabler for secure, efficient, and developer-friendly IoT and edge computing. Feedback from attendees was consistently positive, with many remarking that ELASTIC introduced “something different” compared to other showcases, underlining the novelty and freshness of Wasm in the 6G context. The ELASTIC team—comprising representatives from TUC, ERF, and IMEC—engaged actively with participants, offering hands-on walkthroughs of the demos and discussing how the project’s results contribute to the wider 6G vision. Beyond the exhibition, the event also provided valuable opportunities for networking, exchange of technical insights, and collection of feedback, which will inform the next steps of the project and strengthen its alignment with community needs. In addition, ELASTIC partners contribute to various governance bodies and working groups within the SNS JU 32 and 6G-IA community 33 . Specifically: ● SNS JU Steering Board: TUC participates, contributing to high-level strategic discussions and overall programme governance. ● SNS JU Technical Board: THS participates, providing input on technical directions and priorities for the broader 6G SNS community. ● SNS JU Communication Task Force (Comms): ZEN participates, supporting joint communication activities and coordinated outreach across SNS projects. ● 6G-IA Security Working Group: Dr. Dhouha Ayed (THS) serves as the WG leader, guiding discussions on security challenges and solutions in future 6G systems. ● 6G-Architecture Working Group: THS and TUC participate, contributing to architectural frameworks and integration approaches. ● 6G-Hardware Technologies Working Group: AMA and TUC participate, addressing future hardware needs and technological enablers. 31 “ELASTIC at EuCNC 2025: ELASTIC Highlights Research and Innovation at EuCNC 2025,” https://elasticproject.eu/elastic-at-eucnc-2025-elastic-highlights-research-and-innovation-at-eucnc-2025/ [accessed Aug. 28, 2025]. 32 “SNS JU Working Groups,” smart-networks.europa.eu. https://smart-networks.europa.eu/sns-ju-workinggroups/ [accessed Aug. 28, 2025]. 33 “6G-IA Working Groups,” 6g-ia.eu. https://6g-ia.eu/6g-ia-working-groups/ [accessed Aug. 28, 2025]. ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 53 - August 31, 2025 ● 6G-TMV (Test, Measurement, and Validation) Working Group: TUC participates, focusing on Data Reusability. ● 6G-Pre-Standardization Working Group: AAL participates, supporting early alignment and contributions toward standardisation activities. ● 6G-WiTaR (White Paper, Trials, and Recommendations) Working Group: TUC participates, contributing to trials planning and future recommendations. ● 6G-SNWG (Software Networking AI/ML) Working Group: ZEN participates, addressing AI/ML integration and orchestration aspects relevant to 6G networks. These collaborative and cross-project activities are driven collectively by all ELASTIC partners, each contributing through participation in working groups, joint events, content development, and shared visibility actions. This joint effort underscores the project’s strong commitment to cooperation, knowledge exchange, and achieving broader impact within the European 6G research and innovation community. 2.9 Visual Identity and Communication Assets ELASTIC has developed a strong and recognisable brand identity to support both internal project coordination and external communication efforts. A clear and consistent visual identity plays a key role in building trust, enhancing visibility, and ensuring that all materials produced across the consortium present a unified and professional appearance. At the core of this identity is the project logo, which visually represents ELASTIC’s mission and values, and is used consistently across all communication materials, digital channels, and print assets. In addition to the logo, the project has established a comprehensive set of standardised templates to maintain coherence and quality across various types of outputs. To date, the team has produced a PowerPoint presentation template for general use, a deliverable template to ensure consistency in technical and administrative reports, a Quarterly Technical Progress Report template, a Cost Claim template for financial reporting, and a Technical Deliverable Review Sheet template to guide quality control and internal review processes. Dedicated slide decks have also been created to support presentations at conferences, workshops, and other dissemination events, helping partners communicate project objectives and technical results clearly and effectively. ZEN led the development of these visual materials, ensuring they align with the project’s branding strategy and overall communication objectives. TUC supported the design and preparation of reporting and deliverable-related templates, contributing to the standardisation and ease of use across different partner teams. All partners actively apply these visual assets when preparing presentations, deliverables, event materials, and communication content. This shared approach helps maintain a consistent visual language, reinforces the project’s identity, and ensures clarity and professionalism in every public and internal output. The visual identity elements, including the logo and representative slides are illustrated in Figure 32 and Figure 33 below, with photos and examples to provide a clear overview of how these assets are applied throughout ELASTIC’s communication and dissemination activities. ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 54 - August 31, 2025 Figure 32. ELASTIC Project logo variations Figure 33. ELASTIC Project PowerPoint Presentation Slides Template ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 55 - August 31, 2025 3 Ecosystem Engagement and Stakeholder Involvement Engaging stakeholders and expanding the ELASTIC ecosystem are essential activities to ensure that the project’s outcomes are relevant, widely adopted, and impactful in the long term. These efforts are designed not only to foster meaningful connections, but also to create pathways for active collaboration across different sectors involved in 6G research and innovation, thereby maximising the project’s societal and industrial relevance. Activities in this area focus on identifying and involving key actors from industry (such as network operators, equipment manufacturers, and software service providers), academia (universities, research institutions, and technical networks), standardisation bodies, public authorities, and other related initiatives. Building structured interactions with these groups enables ELASTIC to gather diverse perspectives, validate technical directions, and maximise potential for future adoption and impact. A dedicated focus group has been established, composed of external experts and representatives from various stakeholder categories. This group provides valuable input, feedback, and guidance on project activities, technical approaches, and potential use cases. Their contributions help ensure that ELASTIC remains aligned with the needs and expectations of its broader ecosystem. In practice, this means that technical decisions are not taken in isolation but are shaped by direct feedback from practitioners and decision-makers who are positioned to influence adoption. Engagement efforts include regular updates to stakeholders, targeted outreach campaigns, participation in key events, and direct collaboration opportunities. These activities help keep stakeholders informed about project progress and create channels for two-way communication, enabling the project to adapt and refine its work based on external input. This feedback loop is crucial for ensuring that the project outcomes remain timely, relevant, and trusted. ZEN coordinates the overall approach to ecosystem engagement, ensuring strategic alignment and consistency. UVC, POLITO, TUC, IMEC, and AMA contribute actively by leveraging their networks, engaging with specific technical and regional communities, facilitating dialogue, and gathering feedback that informs project progress. This coordinated and inclusive approach to ecosystem engagement supports ELASTIC’s goal of creating a strong foundation for the successful adoption and real-world implementation of its outcomes within the future 6G landscape. In other words, stakeholder involvement is not treated as an “add-on” but as an integral pillar of the project’s innovation and exploitation strategy. 3.1 Stakeholder Mapping and Target Groups Understanding and prioritising stakeholders is a fundamental element of ELASTIC’s engagement and dissemination strategy. A comprehensive stakeholder mapping document has been developed to identify and classify the different groups relevant to the project’s objectives and outcomes. This mapping exercise distinguishes key target groups across multiple domains, including: ● Industry stakeholders, such as network operators, telecom and cloud infrastructure providers, and technology integrators interested in future 6G orchestration and security solutions. ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 56 - August 31, 2025 ● Research and academic community, including universities, research centers, and technical associations focusing on advanced networking, AI/ML integration, and cybersecurity. ● Policy makers and public authorities, who play a crucial role in defining regulatory frameworks, promoting standards adoption, and supporting secure and trustworthy communication infrastructures. ● Standardisation bodies and working groups, engaged in shaping technical specifications and international standards that will guide future 6G developments. ● End users and developer communities, who contribute to the adoption, testing, and feedback of technologies, and play a key role in validating practical applications and societal impact. The stakeholder mapping document is treated as a living resource and is updated regularly to incorporate new contacts, networks, and interaction feedback obtained throughout the project’s activities. It serves as a central reference to ensure that communication, dissemination, and engagement efforts are strategic, targeted, and responsive to evolving needs. Figure 34 illustrates this mapping using a power–influence matrix. • Stakeholders in the “Manage Closely” quadrant (e.g., network operators, IoT manufacturers) are prioritised for intensive collaboration, as they have both high power and high influence over adoption. • The “Keep Satisfied” quadrant includes policy actors (e.g., the European Commission, ENISA) and alliances with strong shaping power but less direct involvement; these require regular updates and evidence of impact. • “Keep Informed” stakeholders (universities, research labs, AI service providers) are central to research validation and early uptake, and thus require consistent information flow and collaboration. • “Monitor” stakeholders (general public, media, general industry alliances) play a more indirect role but are essential for raising awareness and societal trust. By explicitly linking these groups with tailored engagement strategies (whitepapers, pilots, awareness campaigns, demonstrations), the mapping provides a practical tool for operationalising engagement. It ensures that ELASTIC’s communication efforts are not generic but are adapted to the expectations and potential impact of each stakeholder category. ZEN leads the maintenance and continuous refinement of this mapping process, with active contributions from all partners. Each partner brings insights from their own networks and sector-specific connections, enriching the document with diverse perspectives and real-world relevance. This structured approach to stakeholder identification and prioritisation supports the alignment of outreach activities with ELASTIC’s overarching objectives, maximising impact and fostering stronger relationships within the European 6G ecosystem. ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 57 - August 31, 2025 Figure 34. ELASTIC Project: Stakeholder Mapping 3.2 Focus Group Activities The ELASTIC Focus Group is implemented through the External Expert Advisory Board (EEAB), which provides strategic external input and strengthens the project's alignment with real-world needs. Composed of experienced experts from academia, industry, cybersecurity, and standardisation, the group supports validation of technical directions, advises on relevance and applicability, and ensures that project outcomes remain valuable and impactful. The focus group acts as an independent advisory body, offering perspectives on the project’s objectives, technical developments, and future adoption potential. By engaging with this group early and regularly, ELASTIC strengthens its capacity to address emerging challenges and maintain coherence with evolving 6G priorities in Europe and beyond. The first focus group meeting was held virtually and brought together experts to discuss the project's architecture, security and privacy requirements, and standardisation opportunities. Key insights included recommendations on enhancing modularity in architecture design, strengthening cybersecurity measures aligned with industry best practices, and exploring concrete pathways for contributions to ongoing standardisation activities. The meeting also served as a platform to gather suggestions on use case prioritisation and to discuss potential future collaborations and piloting opportunities. TUC coordinates the focus group activities, facilitating dialogue and preparing feedback summaries. All partners contribute by sharing technical updates, clarifying project details, and following up on recommendations relevant to their domains. Further details on the composition of the focus group and a summary of the first meeting are available on the project website 34 . 34 “ELASTIC External Expert Advisory Board Kick-Off Meeting — Key Insights and Discussions,” https://elasticproject.eu/elastic-external-expert-advisory-board-kick-off-meeting-key-insights-and-discussions/ [accessed Aug. 28, 2025]. ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 64 - August 31, 2025 • Provide a structured analysis of where existing standards fall short in addressing ELASTIC’s technical domains, such as orchestration, WebAssembly integration, and security automation. • Act as a roadmap for future contributions, guiding post-project engagement in standards bodies and supporting the long-term impact of ELASTIC’s outputs. • By complementing workshops and activity development with this forward-looking resource, ELASTIC ensures that its contributions are both relevant to current discussions and strategically positioned for future influence. 4.2 Participation in Standards Developing Organisations (SDOs) Several ELASTIC partners have made measurable progress in contributing to international and European standardisation efforts. Their work spans the elaboration of new standards, revisions of existing ones, and active participation in technical groups and committees. These efforts ensure that ELASTIC’s results remain aligned with recognised frameworks while also opening pathways for the project’s innovations to influence the standards that will underpin future 6G ecosystems. A key example comes from W3C and the WebAssembly community, where IMEC has been actively involved in the WASI subgroup. IMEC contributed to the development of two new standards that extend WebAssembly’s secure interaction with hardware: • WASI-USB 43 : An API providing WebAssembly applications with access to external hardware via the USB BUS. This specification was voted to Phase 1 in 2024 and represents an important step toward enabling trusted device interaction in Wasm-based environments. • WASI-I2C 44 : An API enabling secure access to external hardware via an I2C bus, allowing Wasm applications to integrate seamlessly with sensors and embedded devices. This specification advanced to Phase 2 in 2024, reflecting growing maturity and adoption within the standardisation process. • WASI-GPIO 45 : An API providing secure general-purpose input/output (GPIO) access for WebAssembly applications. This standard proposal, directly related to ELASTIC’s WasmHAL component (T2.1, T4.1), has been adopted by IMEC and will be furtherdeveloped to support access to low-level sensors by edge devices. These contributions are directly relevant to ELASTIC’s objectives and position IMEC at the forefront of the WebAssembly standards ecosystem, ensuring that the project’s technical focus areas are represented in international best practices. At OASIS, TUC contributed to the revision of the Collaborative Automated Course of Action (CACAO) v2.1 standard 46 . CACAO defines schemas for creating, documenting, and sharing automated cybersecurity playbooks, providing a foundation for collaborative and standardised 43 “wasi-usb,” GitHub - WebAssembly, https://github.com/WebAssembly/wasi-usb [accessed Aug. 29, 2025]. 44 “wasi-i2c,” GitHub – WebAssembly, https://github.com/WebAssembly/wasi-i2c [accessed Aug. 29, 2025]. 45 “wasi-gpio,” GitHub – WebAssembly, https://github.com/WebAssembly/wasi-gpio [accessed Aug. 29, 2025]. 46 “CACAO Security Playbooks v2.0,” OASIS, https://docs.oasis-open.org/cacao/securityplaybooks/v2.0/cs01/security-playbooks-v2.0-cs01.html [accessed Aug. 29, 2025]. ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 65 - August 31, 2025 incident response. The revision addressed operational gaps identified through industry use and aligns strongly with ELASTIC’s emphasis on automation and cybersecurity. TUC has also played an important role in the renewed activities of the FIRST.org Automation Special Interest Group (SIG). Restarted in collaboration with IHAP and GÉANT TF-CSIRT, the group has held three dedicated meetings, focusing on incident response automation best practices, documented guidelines, tool compilation, and building a shared understanding of automation in cybersecurity operations. Through their active participation, TUC contributed to strengthening this international community’s focus on advancing operational security automation. At the European level, TUC has contributed to the ENISA Ad-hoc Working Group on SOCs, in particular the Report on Playbooks and Automation. This work analysed existing cybersecurity playbooks, identified gaps, and provided recommendations to support European standardisation of automated response capabilities. These outputs will feed into wider EU initiatives aimed at strengthening SOC operations and incident response, underlining the relevance of ELASTIC partners’ expertise for European cybersecurity policy. Contributions also extend to ETSI, where THD has engaged with the NFV Security Working Group. The group is advancing attestation architectures for NFV environments, an area directly linked to ELASTIC’s research on remote attestation. Earlier reports, such as ETSI GR NFVSEC 018 V1.1.1 (2019), laid the groundwork, and ELASTIC partner contributions may help shape ongoing specifications. Building on this, THD has initiated direct contact with the ETSI NFV Chair to explore further collaboration. Two areas of mutual relevance have already been identified: attestation (in particular remote/distributed attestation aligned with ETSI NFV SEC) and lightweight security orchestration. A joint meeting is being planned, during which ETSI NFV will present its structure and procedures, and ELASTIC will showcase its framework and technical advances in these domains, while also exploring additional opportunities for contribution. ERF has continued contributing at the IETF ASDF and CoRE working groups and at the IRTF T2TRG for research and development of protocols and data model technologies that can be used to realise ELASTIC use cases for scalable in-network data processing. Finally, ERS and THD have continued their long-standing involvement in 3GPP, with active participation across multiple working groups (e.g., SA1, SA2, SA3, CT6). Their contributions cover areas including next-generation network security, authentication, and service architecture—all directly relevant to ELASTIC’s exploration of secure orchestration for 6G networks. Taken together, these contributions show the breadth of ELASTIC partners’ engagement: • Elaboration of new standards: e.g., WASI-USB and WASI-I2C at W3C, expanding WebAssembly’s scope in secure hardware integration. • Revisions of existing standards: e.g., CACAO v2.1 at OASIS and NFV Security at ETSI, which update and strengthen existing frameworks, and WASI-GPIO at W3C. • Participation in technical groups and committees: e.g., FIRST.org Automation SIG, ENISA Ad-hoc Working Group, and 3GPP, where partners influence operational practices and global architectures. ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 66 - August 31, 2025 Through this multi-level engagement, ELASTIC partners ensure that the project’s technical results are not only aligned with current frameworks but also actively shaping the standards that will guide future developments in orchestration, confidential computing, and automation. 4.3 Open-Source Community Engagement In parallel with formal standardisation efforts, ELASTIC partners have actively contributed to open-source projects and ecosystems, recognising them as a key pathway for adoption, validation, and long-term sustainability of the project’s outputs. These contributions range from the creation of entirely new projects to patches and feature enhancements in existing frameworks, all directly supporting ELASTIC’s technical objectives. Open-source engagement ensures that innovations from ELASTIC are visible to academic and industrial communities and integrated into practical environments where they can be tested, reused, and extended by a global developer base. Key contributions include: ● Propeller Orchestrator (AMA) 47 : Released under the Apache 2.0 licence as an independent project, Propeller is a lightweight orchestrator designed to manage the deployment of Wasm applications at the edge. The open-source release enables broader community experimentation, allowing developers to test orchestration strategies and provide feedback that directly informs ELASTIC’s research directions. ● LLVM Compiler Infrastructure (THS): THS has contributed runtime safety features to LLVM, including a new optimisation flag for WebAssembly compilation (merged upstream) 48 and a prototype stack-smashing protection (SSP) mechanism for Wasm 49 . These contributions strengthen memory safety and reduce vulnerabilities, directly improving the security posture of Wasm workloads and IoT applications. ● Wasm Ecosystem (IMEC): IMEC has released several tools to extend the usability of WebAssembly within distributed and cyber-physical environments: ○ wasm-operator 50 : A Kubernetes operator that can run other operators as Wasm modules, allowing them to be swapped to disk when not in use, thereby reducing memory footprint and improving efficiency. ○ kube-rs patch 51 : Extended kube-rs to support wasm-operator integration. ○ WASI reference implementations: Reference APIs for WASI-I2C 52 , WASIUSB 53 , and WASI-GPIO 54 together with wasi-embedded-hal 55 , provide secure hardware interactions through WebAssembly and support adoption of emerging WASI standards. 47 https://github.com/absmach/propeller 48 https://github.com/llvm/llvm-project/pull/95208 49 https://github.com/ThalesGroup/llvm-project/tree/new-wasm-ssp 50 https://github.com/idlab-discover/wasm-operator 51 https://github.com/idlab-discover/kube-rs 52 https://github.com/idlab-discover/i2c-wasm-components 53 https://github.com/idlab-discover/usb-wasm 54 https://github.com/idlab-discover/masters-jarno-vanruymbeke 55 https://github.com/idlab-discover/wasi-embedded-hal ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 67 - August 31, 2025 ● TEE Hardware Abstraction Layer (LUN) 56 : LUN has released teehal, an opensource TEE Hardware Abstraction Layer, providing a foundation for portable and secure execution of trusted workloads across heterogeneous platforms. Beyond code contributions, ELASTIC partners are also engaged in community-building activities: ● Confidential Computing Consortium (CCC): THD presented ELASTIC’s results at the Remote Attestation SIG, while AAL maintains regular participation in discussions on confidential computing and attestation practices. These activities ensure that ELASTIC’s technical outputs are aligned with wider community efforts on TEEs. ● WasmCloud Community (AAL): AAL has engaged with this community around multi-platform verification, with ELASTIC’s work recognised as potentially valuable for future confidential computing initiatives and Wasm orchestration models. By pursuing a dual-track approach of formal standardisation and open-source adoption, ELASTIC ensures that its results are both formally recognised in international frameworks and practically validated in real-world environments. This strengthens project visibility, accelerates uptake, and supports the long-term sustainability of its technical outputs. 4.4 Outlook Looking ahead, ELASTIC will continue to strengthen collaboration between partners, broaden contributions to additional SDOs, and maintain active involvement in open-source communities. This dual focus ensures that results are represented both in formal standards and in practical implementations, supporting their long-term adoption and relevance. Future efforts will focus on four main directions: 1. Expanding standardisation impact: Partners will strengthen their involvement in ongoing work at W3C, 3GPP, ETSI, ENISA, FIRST.org, and OASIS, while also exploring opportunities to engage with additional SDOs where ELASTIC technologies are relevant. 2. Deepening open-source adoption: Building on the release of tools such as Propeller Orchestrator, wasm-operator, LLVM enhancements, and teehal, partners will further develop and maintain these projects, encourage community uptake, and ensure longterm sustainability through active participation in developer ecosystems. 3. Bridging standards and open-source: By aligning reference implementations (e.g., WASI-USB, WASI-I2C, WASI-GPIO) with ongoing standardisation processes, ELASTIC partners will help ensure that formal specifications are backed by tested, widely available code. This integration strengthens the credibility of contributions and accelerates adoption. 4. Exploring Horizon Booster for Standardisation: The consortium will consider applying to HSbooster.eu, the Horizon Booster initiative that provides free consultancy services to EU-funded projects aiming to amplify their impact on standardisation. This support could help ELASTIC target the most relevant committees, streamline contributions, and improve visibility, thereby scaling its standardisation impact and strengthening its legacy beyond the project. 56 https://github.com/eit-sns/teehal ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 68 - August 31, 2025 Through these activities, ELASTIC is well positioned to ensure that its results extend beyond the lifetime of the project, contributing to the creation of secure, trustworthy, and efficient 6G services. ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 69 - August 31, 2025 5 Exploitation Activities Deliverable D6.1, submitted at Month 6, defined the initial exploitation vision of the ELASTIC project and set the foundation for long-term impact beyond the project’s lifetime. It established a framework based on three exploitation streams - commercial, research, and technological - ensuring that each outcome of the project would follow a tailored path aligned with the nature of the result and the intentions of the involved partners. The deliverable outlined the importance of transforming innovative ideas into marketable products and services while supporting open science, knowledge transfer, and compliance with EU priorities for sustainability and societal benefit. D6.1 also presented the phased exploitation plan (market insights, business modelling, business plan, and go-to-market strategy), accompanied by a preliminary business model canvas and an initial mapping of KERs. These tools provided the baseline for tracking, refining, and developing each result’s exploitation potential. Additionally, it introduced a dual-licensing strategy to combine open-source community engagement with professional services and proprietary business offerings. Importantly, D6.1 also included individual exploitation strategies for each partner (detailed in Section 5.4), recognising that exploitation must be adapted to the diverse institutional goals of academic, industrial, and SME participants. Together, these individual plans highlighted the role of ELASTIC not just as a research project, but as a driver of sustainable growth, industrial competitiveness, and academic progress across the European digital ecosystem. Deliverable D6.2 serves as a mid-project summary of exploitation activities, offering an updated plan and refined methodology that builds upon the foundation established in D6.1. The exploitation strategy continues to be structured around the three streams - commercial, research, and technology - under the overall framework of Innovation Management. In D6.2, the technology stream has been expanded into “Business and Technology exploitation”, highlighting the importance of practical uptake and application of ELASTIC results in realworld scenarios. A key focus of D6.2 is the individual exploitation analysis of all ELASTIC components, examining each asset’s exploitation potential, target users, application domains, and anticipated path to uptake. These analyses have produced consolidated exploitation findings, revealing common trends, complementary opportunities, and cross-partner synergies. Based on this bottom-up analysis, the deliverable also proposes an updated set of potential KERs, reflecting the project’s technical progress and strategic alignment with stakeholder and market needs. D6.2 thus updates the initial plans presented in D6.1, reflects the current maturity of project outcomes, and sets the stage for focused exploitation actions and a final roadmap to be delivered in D6.3 (due M36). 5.1 Plan and methodology The exploitation work in ELASTIC has been structured into three sequential phases, each building upon the previous to move from strategic alignment toward actionable innovation outcomes. This phased approach ensures that the consortium not only identifies and develops technical results but also translates them into credible, sustainable pathways to impact - commercially, technologically, or through further research. The sections that follow provide an overview of the key activities and milestones achieved in each phase. Figure 36 below ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 70 - August 31, 2025 illustrates the ELASTIC exploitation roadmap, highlighting the core activities associated with every phase. Figure 36. ELASTIC Exploitation Roadmap Exploitation Phase I (M01–M06) Phase I focused on establishing a strong and cohesive foundation for exploitation activities across the ELASTIC consortium. During this phase, a consortium-wide exploitation strategy was defined, outlining clear roles, shared objectives, and strategic priorities tailored to the diverse profiles of the partners involved. This common framework fostered alignment around core concepts such as value creation, intellectual property, and the three primary exploitation pathways - commercial, technological, and research-oriented. A preliminary business model was developed, accompanied by initial market insights to begin contextualising the project’s innovation potential within relevant ecosystems and value chains. One of the key achievements of this phase was the early identification of promising technical assets emerging from the WPs. This initial mapping of assets enabled the consortium to anticipate where innovation could take shape and highlighted components that might later evolve into integrated value propositions. In parallel, each partner prepared an individual exploitation plan, outlining their specific interests in ELASTIC results and preferred exploitation mechanisms. These plans captured the distinct ambitions and capabilities of each organisation while also revealing areas of potential synergy and complementarity. Overall, Phase I delivered a structured exploitation strategy, a preliminary landscape of exploitable components, and a shared value-driven mindset, laying the groundwork for the in-depth component-level analysis conducted in Phase II. Exploitation Phase II (M07–M18) Phase II of the exploitation work, documented in D6.2, built directly on the strategic groundwork laid in Phase I by shifting focus toward the systematic identification, analysis, and structuring of individual exploitable results produced by the technical WPs (WP1–WP4). The core objective of this phase was to assess the exploitation potential of each ELASTIC component through a detailed bottom-up process. ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 71 - August 31, 2025 To ensure a structured and harmonised process, the consortium adopted a methodology based on the Horizon Results Booster (HRB) framework 57 . An enhanced results collection template was developed, extending the HRB format to reflect the specific context and scope of the ELASTIC project. This collector template (Table 5 below) was distributed to all partners and requested inputs on aspects such as: ● Description of the result, WP/task origin, and contributing partners ● Technology Readiness Level (TRL) progression and future development outlook ● Value proposition, target users/stakeholders, and user needs addressed ● Foreseen exploitation path (e.g., internal use, licensing, open source, standardisation) ● IPR considerations, competitive landscape, and associated risks. Particular emphasis was placed on situating each result within a realistic exploitation context, including its relevance in the broader value chain and potential adoption routes. The analysis revealed a range of emerging patterns and complementary functionalities, facilitating the identification of synergies and clustering opportunities among components and partners. As a result, a first set of candidate KERs is proposed in D6.2 - grounded not only in technical potential and maturity (typically TRL 2–4) but also in strategic alignment with the ELASTIC concept. These early KERs will undergo further refinement and validation in the next phase, in close collaboration with the architecture and demonstrator teams. Importantly, the identification of these KERs was strongly informed by the definition of ELASTIC’s architecture, the design of the demonstrators, and the initial integration planning. These technical activities provided essential context regarding how individual components are intended to interact and contribute to system-level capabilities, thereby helping shape a realistic and technically grounded exploitation strategy. Table 5: Template for Exploitable Results Analysis Exploitable Result Number X If Other Please Specify Comments (from the Horizon Booster template) ELASTIC amended entries and further guidance are described here Name of Result <Please Provide the name of your result, i.e., component name> Partner Name Type of Result <Examples include software, hardware, methodologies, standardisation framework, etc.> Associated WP & Task & Demonstrator (Use Case, Scenario) WPX/T.X, <Demonstrator Name> <Please mention the WP/Task/ Demonstrator associated with your result> Brief Description - what it does <Please Provide a description of the result you are developing within the project> Background IP <Is there a background IP (know-how, knowledge) from your organisation to support the development of your result within the project?> Current/ Expected TRL <What is the current and expected Technology Readiness Level of your result> <Use of IP/Result> 57 https://www.horizonresultsbooster.eu ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 72 - August 31, 2025 Exploitation Use Direct Commercialisation/ University Course/ Training/ Direct Licensing to Customer/ Indirect Licencing through Vendor/ Assignment of IPR (Sell Rights of IP)/ Research Services/ Further R&D Projects/ Spin-off Company/ New Standard/ Other <How are you planning on using your results after the end of the project. Select one option from the dropdown list and if you include more than one option please use the space provided in the D Column> <Is IP available or in progress as a result of ELASTIC work? If yes, please provide a short one-line description. Is the result (component) related to or dependent on any other result (component) of ELASTIC, and if so, which ones?> Can it be Protected? Yes/ Potentially/ No IPR Protection Method Trade Secret/ Utility Model/ Patent/ Copyright/ Design Rights/ Trademark/ Industrial Design/ Database Rights/ N/A <You can find detailed description of the IPR Protection methods below> Customers/ Users/Target Audience 1. 2. 3. 4. < Please mention the stakeholders that would be interested in your result. Ideally, industries and markets should be mentioned. If the results is clearly research-oriented, refer to relevant stakeholders> Pains of customers/Users 1. 2. 3. 4. <What are the issues end users face that make your result necessary?(e.g., Lack of security, Loss of time, ineffective processes, Lack of knowledge etc)> <Describe the end-user problem that is solved, or the end-user need in mind. Describe any identified business requirements. If possible, provide corroborating market insights, facts or indicators including appropriate references (e.g., analyst reports, etc.)> Benefit of Customers/Users 1. 2. 3. 4. <What is the benefit that your result is bringing to these stakeholders compared to the state of the art?> <Articulate the value proposition. Can the value be quantified or is there any metric that can be used to quantify the value?> Target audience <Describe the target audience using the result as well as the beneficiary. Consider technology and solutions providers as one category. Consider enduser industry segment or vertical as another category, i.e., the "ultimate beneficiary". Please provide concrete examples of market actors when possible.> Business model <Describe your intended business model and any go-to-market model. Do you have a monetisation model (beyond licensing)?> Exploitation channels <Describe the exploitation channels you have under consideration (e.g., open source, standards, industry alliances, special interest groups, …)> <Risks & Challenges> Market PositionDefine the place the product/service aims to occupy in the market, e.g., is it a premium offering, a budget solution, or a niche product? ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 73 - August 31, 2025 Deployment Barriers 1. 2. 3. 4. <What are technical challenges that you may face in further developing your result?(e.g., increase TRL, to be used by customers, etc) > <Does the solution bring any penalty, e.g., cost, performance? > Other Challenges 1. 2. 3. 4. <Are there any other organisational or economic challenges that you may face in further developing your result? (e.g., lack of funding, heavy investment needs, lack of infrastructure, lack of market needs)> Mitigation Measures 1. 2. 3. 4. <How could these challenges be mitigated?> Other Solutions (Current State of the Art) 1. 2. 3. 4. <Please mention other solutions similar to your result> <Describe the competitive landscape> *IPR Protection Catalogue Method Description Internal Internal protection refers to safeguarding intellectual property within the organisation without applying for external legal protections. Know-How Know-how refers to the practical knowledge, skills, and expertise that an organisation or individual possesses, which is not formally registered but provides a competitive edge. Patent A patent is an exclusive right granted for an invention related to a product or process that provides a new way of doing something, or that offers a new technical solution to a problem. A patent provides patent owners with protection for their inventions. Protection is granted for a limited period, generally 20 years. Utility models Utility models are similar to patents as a protection method by granting a limited exclusive right. They are usually cheaper to obtain, have a shorter term (around 10 years) and less stringent patentability requirements. They are well suited for protecting inventions that make small adaptations or improvements at existing products. Industrial Design An Industrial Design refers to the ornamental or aesthetic aspects of an article. A design may consist of threedimensional features, such as the shape or surface of an article or two-dimensional features such as patterns, lines, or colour. Trademark A trademark is a distinctive sign that identifies certain goods or services produced or provided by an individual or a company. The system helps consumers to identify and purchase a product or service based on whether its specific characteristics and quality as indicated by its unique trademark meet their needs. Copyright Copyright is a legal term used to describe the rights that creators have over their literary and artistic works. Works covered by copyright range from books, music, paintings, sculpture and films, to computer programs, databases, advertisements, maps and technical drawings Trade secrets Trade secrets are IP rights on confidential information which may be sold or licensed. The unauthorised acquisition, use or disclosure of such secret information in a manner contrary to honest commercial practices by others is regarded as an unfair practice and a violation of the trade secret protection. Exploitation Phase III (M19–M36) The upcoming Phase III will focus on business planning and the long-term sustainability of results. Building on the candidate KERs identified in Phase II, this phase will finalise the selection of KERs based on their technical maturity, integration readiness, and strategic relevance to ELASTIC’s value proposition. A key element of Phase III is the active participation in the HRB initiative, a dedicated support mechanism offered by the European Commission to maximise the impact of Horizon Europe projects. By joining the HRB, ELASTIC partners will gain access to tailored expertise, coaching, and facilitation services designed to accelerate the exploitation and market uptake of project results. ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 80 - August 31, 2025 data exposure and unauthorised access. WebAssembly adoption is hindered by limited runtime incompatibilities, non-standard permission models, integration complexity, and limited hardware access. Developers struggle with poor tooling for eBPF and observability, making debugging and performance tuning complex and inefficient. Networking performance suffers from low visibility, lack of scalable solutions like distributed eBPF, and networking layers suffering from low resource utilisation and opaque metrics, while AI/ML workloads are often too demanding for edge deployments. Intrusion Detection Systems are difficult to scale and maintain, especially with AI-based approaches. Finally, observability in serverless and Wasm environments lacks lightweight, cost-effective solutions, complicating fault tracing and performance monitoring. Overall, the challenge is to balance performance, security, and usability in constrained, distributed, and increasingly evolving dynamic environments. These pain points collectively highlight the need for more integrated, secure, and “resource-aware” infrastructure solutions. A summary of the various identified pain groups according to the main concerns is provided below. Security & Confidential Computing. There are fundamental trust and protection gaps in executing sensitive workloads, especially in distributed systems. This includes data exposure risks, complex attestation, vendor lock-in, and lack of standardised security mechanisms, which slow down confidential computing adoption and compromise edge device integrity. Orchestration & Resource Constraints. Modern orchestration frameworks (like Kubernetes) are too heavy for resource-constrained IoT devices. There is a lack of lightweight, real-timecapable orchestrators and inefficient cloud-to-edge migration, with complexity and performance tradeoffs preventing effective deployment at scale. Networking, eBPF & Observability. Cloud-native and edge systems suffer from network bottlenecks, low resource efficiency, and lack of fine-grained visibility. eBPF-based solutions face debugging complexity, scaling issues across nodes, and lack of tooling, which slow development and expose systems to security risks. WebAssembly (WASM) Challenges. Adoption of WASM in edge and serverless environments is blocked by platform limitations, lack of standards for permissions, poor hardware integration, and steep learning curves. WASM runtimes lack fine-grained control, debuggability, and broad platform support, limiting adoption in embedded/IoT contexts. Federated/Split Learning & Edge ML. Deployment of Federated or Split Learning on edge devices is hindered by lack of lightweight, secure frameworks, high technical complexity, and compliance challenges. Performance suffers when dealing with resource-constrained devices, heterogeneous data, and compute-intensive models. Intrusion Detection & Threat Management. Traditional IDS systems are resource-intensive, hard to scale, and slow to adapt to emerging threats. AI-powered IDS adds compute burden, and integration with existing tools is complex and brittle, making security harder to maintain effectively over time. Authorisation & Access Control. There is a mismatch between modern access control models (e.g., ABAC) and the limited compute capacity of edge devices. WASM environments also lack standardised ways to define and enforce permissions, complicating secure deployments. Mobility, Prediction & AutoML. Networks face security challenges from mobility, with poor prediction models and limitations in AutoML making proactive security and adaptive orchestration unreliable. ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 81 - August 31, 2025 User gains and benefits identified by the ELASTIC partners Based on the exploitation collector, ELASTIC has identified a set of user gains and benefits to exploit in our research which in summary is the following. Secure and efficient ML training is now achievable on heterogeneous devices through the combination of Split Learning and TEEs, enabling privacy-preserving analytics even for non-experts. Our focus on lightweight orchestration frameworks targets reduced resource consumption, enables deployment on microcontrollers and across cloud-to-edge pipelines. The advancements in scope on remote attestation, enclave I/O, and encryption boost trust and data confidentiality, while our work on WebAssembly gains improved security, configurability, and hardware interoperability. We foresee major gains in networking and observability through enhanced eBPF tooling, real-time metrics, and distributed state handling. Intrusion detection can be made faster, more accurate, and energy-efficient with AI and reconfigurable hardware. Our work on fine-grained access control, flexible authorisation, and support for multi-layered security policies targets secure workload isolation. The main groups of identified aggregated ELASTIC gains and benefits are the following. Improved Security & Confidential Computing. Workload trust is improved through secure enclaves, attestation, and lightweight encryption methods. Improved solutions for remote attestation and multi-TEE migration to enhance protection of sensitive data, privacypreservation, and fostering wider adoption of confidential computing in edge and cloud environments. Orchestration across Edge-to-cloud Continuum & Improved Resource Efficiency. Lightweight, low-footprint orchestration solutions reduce resource usage, enable deployment on constrained devices, and simplify cloud-to-IoT pipelines. These advancements support realtime Wasm workloads and tailored security operations, decreasing operational overhead while increasing orchestration efficiency and scalability. Enhanced Networking, eBPF & Observability. Network performance and observability are enhanced through real-time, low-overhead insights, RDMA optimisation, and distributed eBPF state sharing. Improved tooling accelerates development, reduces debugging time, and supports better infrastructure decisions for modern, performance-sensitive environments. Improved Intrusion Detection & Threat Management. The use of AI and hardware acceleration for real-time, low-latency threat detection are expected to be energy-efficient, scalable, and well-suited for edge deployments, enhancing detection accuracy while reducing system load and central resource dependency. Improved WASM Capabilities. Security, portability, and maintainability of Wasm workloads are improved through automated privilege controls, device-specific permissions, and standardised interfaces. Evolved tools can support long-term firmware updates and better hardware access, enabling secure, flexible deployment across constrained and heterogeneous environments. Enhanced Authorisation & Access Control. Access control is enhanced with fine-grained, flexible policies that span multiple workloads and devices. Standardised permission handling and operator-defined policies improve workload isolation, simplify security audits, and support secure orchestration in dynamic, multi-tenant environments. Evolved Federated Learning & Edge ML. Solutions that combine TEEs with Federated Learning enable secure, efficient ML training across diverse edge devices and that can be offered as-a-Service. They target simplification of deployment for non-experts, ensure ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 82 - August 31, 2025 regulatory compliance, and maintain performance with heterogeneous data and computational constraints. Mobility, Prediction & AutoML. Robust AutoML frameworks can support accurate mobility prediction, even in adversarial conditions. Open-source tools and data enable research and development of mobility-aware orchestration and security mechanisms for mobile networks and dynamic infrastructure environments. 5.3 ELASTIC Potential Key Exploitable Results A Key Exploitable Result (KER) is defined as a result - be it a technology, software component, integrated system, methodology, or architectural pattern - developed within the project that holds significant potential for real-world uptake and sustained impact beyond the project’s lifetime. A KER typically represents a concrete and identifiable output that can be transferred into commercial, open-source, or internal exploitation pathways by one or more project partners. In ELASTIC, the identification of KERs serves as a critical step in operationalising the project's exploitation strategy. KERs function not only as outputs of technical WPs and demonstrators but also as vehicles for partner commitment, stakeholder engagement, and market-oriented innovation. Each KER is expected to carry a clear value proposition, technical maturity, identifiable ownership, and a realistic sustainability trajectory. During the first half of the project, the consortium has conducted a structured review of all project results, components, and demonstrator use cases. This process included: ● Partner input via dedicated exploitation surveys and trackers ● Assessment of reuse potential, readiness level, and integration in demonstrators ● Initial analysis of IPR considerations and partner ownership This analysis, combined with emerging architectural patterns and cross-cutting technology stacks (e.g. WebAssembly, Confidential Computing, Orchestration), has enabled the extraction of a preliminary list of five KER candidates. These have been selected based on their alignment with the ELASTIC value proposition, early signs of stakeholder or market relevance, and the presence of committed partners ready to explore exploitation potential further. This list remains open to refinement in Phase III as additional validation and maturity assessments are conducted. The Table 6 below summarises the current KER candidates identified through the mid-term exploitation review. These KERs represent distinct strands of innovation within ELASTIC and collectively demonstrate the project's ambition to push forward trusted, distributed intelligence across the edge-cloud continuum. They address key industrial and societal needs, including secure IoT, workload portability, and platform trust. Each KER includes a set of underlying components or enabling technologies developed across multiple WPs. While some KERs (e.g. KER1 and KER2) focus on integrated system-level solutions, others (e.g. KER3, KER4, KER5) emphasise modular, reusable assets that can be adapted to various deployment environments or industry verticals. ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 83 - August 31, 2025 Table 6: ELASTIC Potential Key Exploitable Results KER# Title Scope Contributors KER1 6G-embedded IoT data fabric Integration of ELASTIC components into a cohesive platform for orchestrating secure, realtime data processing and analytics at the edge, supporting massive IoT scenarios. ERF, UVC, IMEC, THS, ZEN, AMA, POLITO, AAL, TUC KER2 Privacy-preserving and secure on premise to public cloud computing platform End-to-end solution enabling secure workload migration using confidential computing, attestation, and secure key handling across cloudedge continuum. THD, AAL, UVC, LUN, TUC KER3 Secure Wasm-native cloud-to-edge workload orchestrator (Propeller Orchestrator) A highly portable and extensible orchestrator by AMA, enabling dynamic deployment of Wasmbased workloads AMA KER4 WebAssembly Platform for Distributed Trusted Systems A full-stack Wasm runtime foundation combining runtime optimisation, platform integration, hardware-level access, secure communication, and enforcement tooling. IMEC, AMA, POLITO, AAL KER5 Confidential Computing, Security & Privacy Toolkit Set of interoperable security components supporting TEE lifecycle management, attestation, encryption, and policy enforcement. THD, THS, ERF, UVC, AAL, LUN 5.3.1 KER #1: 6G-embedded IoT data fabric Overview This KER delivers a trusted data fabric framework that extends 6G infrastructures beyond connectivity services to provide secure and data-oriented capabilities as an extended native infrastructure system function. The data fabric addresses a number of data integration challenges, and enables a pervasive approach to employing ML and AI at scale in a number of highly distributed concurrent applications. Within ELASTIC, the data fabric use case focuses on IoT applications, enabling real-time data integration, interoperability, and trustworthy execution across heterogeneous environments including a constrained edge running on microcontrollers. By combining Confidential Computing, WebAssembly portability, and edgeto-cloud orchestration, it supports large-scale, distributed applications that require low latency, high reliability, and end-to-end trust. Why this KER was Selected KER1 was selected because it directly contributes to ELASTIC’s objective of secure, trustworthy orchestration of services across the computing continuum. It responds to key industrial challenges such as data explosion at the edge, interoperability of diverse data sources, and the need for privacy-preserving analytics. The convergence of TEEs, portable runtimes, federated learning, and edge computing creates a viable solution for scaling AI-enabled industrial processes, positioning this KER as a cornerstone for data-driven 6G systems. Demonstrator Relevance The data fabric is the core of Demonstrator 1, and is validated in a manufacturing use case through three industrial applications: predictive maintenance, cross-factory data sharing, and real-time robot control. These scenarios showcase its ability to support concurrent, highly distributed applications while ensuring security, trust, and efficient data handling. The ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 84 - August 31, 2025 demonstrator provides a concrete validation of how data fabric concepts can be applied in manufacturing to improve resilience, automation, and decision-making. Supporting Components The KER builds on several ELASTIC technologies, including: ● Wasm-operator (IMEC) ● Light-weight Security orchestrator for Edge devices (THS) ● Federated Learning Toolbox (ZEN) ● TEE Software Management Agent (UVC) ● Reliable enclave migration protocols (AAL) ● Propeller Orchestrator (AMA) ● Data protection at-rest at the edge with TEE solution (THS) + Hardware-based cryptography module (TUC) ● WASI Security (IMEC) ● WasmHAL Hardware (IMEC) ● Static eBPF code security Analyser (POLITO) ● Static analysis of interaction between Wasm modules (POLITO) ● Accelerated microservices interconnection (POLITO) ● eBPF distributed state synchronisation (POLITO) ● NETTO (POLITO) ● AI Intrusion Detection/Prevention System (TUC) ● Observability framework for serverless workloads (ERF) ● Multi-platform attestation component (ERF) ● Light-weight Attribute-based Access Control (ABAC) solution (THS) Preliminary Value KER1 provides a pervasive, hyperscale solution for industries seeking to unlock the full value of IoT and AI by addressing the complex, multi-dimensional challenge of data integration. This capability—achieved at scale—is the core differentiator, enabling seamless combination and utilisation of heterogeneous industrial data. While confidentiality, integrity, and compliance remain essential preconditions for viability, ELASTIC uniquely delivers trusted data integration that meets these constraints by design. This creates new opportunities for telecom operators and solution providers to extend their offerings with data-oriented services, while end-user industries gain resilient data integration to support near real-time decision-making and secure data sharing. Potential beneficiaries include manufacturing, energy and utilities, transport, and logistics, where integration at scale directly underpins industrial automation and future datadriven services. 5.3.2 KER #2: Privacy-preserving and secure on premise to public cloud computing platform Overview This KER delivers a comprehensive platform that enables the secure migration of sensitive IT services from on-premise infrastructures to public cloud environments. The platform addresses critical security, privacy, and compliance challenges through the integration of Confidential Computing technologies, including TEEs, Remote Attestation, Secure Key Management, and Wasm-based runtime abstraction. ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 85 - August 31, 2025 The core value proposition lies in combining end-to-end data protection with runtime portability and verifiability, enabling industrial actors - particularly those in regulated sectors - to adopt cloud services without compromising on security, confidentiality, integrity, or control. Why this KER was Selected This KER was selected as a key exploitable result due to its strong alignment with ELASTIC’s core objectives - namely, enabling secure and trusted orchestration of services across heterogeneous infrastructures. It directly addresses one of the most pressing challenges in industrial digital transformation: how to migrate sensitive IT services to the cloud without compromising security, privacy, or regulatory compliance. Several factors informed the selection: ● Demonstrated integration in Demonstrator 2 ● Relevance to regulated industrial solution providers like THD ● Clear alignment with ELASTIC’s objectives around secure orchestration and trust ● Integration of multiple ELASTIC components from WP1, WP2, WP3, and WP4 ● Strong applicability across industry verticals requiring IT/OT convergence Demonstrator Relevance In Demonstrator 2, this KER is validated through the secure migration of the Badge Request Tool (BRT) - a legacy IT application handling sensitive data - to a public cloud environment. The demonstrator combines Wasm-based execution with TEEs, attestation, and secure orchestration, offering a blueprint for trustworthy cloud adoption in industrial settings. Supporting Components This KER is composed of interoperable components developed across the project: ● WASI Flexibly-defined Capabilities (AAL) ● TEE Software Management Agent (UVC) ● Propeller Orchestrator (AMA) ● WasmHAL-Trust (LUN, UVC) ● Reliable Enclave Migration Protocol (AAL) ● Remote Attestation Platform (THD) ● Key Broker Service (THD) ● AI-based Intrusion Detection System (TUC) Preliminary Value KER2 offers a practical and secure solution for the migration and operation of sensitive IT services both to and in the public cloud, while preserving data confidentiality, runtime integrity, and regulatory compliance. Its value lies in: ● Enabling secure and confidential execution of legacy workloads via TEEs. ● Reducing platform vendor lock-in through Wasm-based portability. ● Offering a replicable migration pathway for security-sensitive industrial applications. Potential beneficiaries include industrial actors in regulated domains, IT/OT system integrators, and cloud infrastructure providers seeking trustworthy execution frameworks. ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 86 - August 31, 2025 5.3.3 KER #3: Secure Wasm-native cloud-to-edge workload orchestrator (Propeller Orchestrator) Overview Propeller is a Kubernetes-free, lightweight orchestration platform developed by AMA to manage Wasm workloads across the cloud–edge continuum — including highly constrained environments such as microcontrollers and embedded RTOS devices. It enables event-driven, Function-as-a-Service (FaaS) execution using MQTT-based messaging and serves as a core orchestration layer for latency-sensitive, distributed workloads. While Propeller itself does not provide security mechanisms, it is designed to integrate seamlessly with trusted environments (e.g., TEEs), enabling the orchestration of workloads that benefit from secure and attested execution. Why this KER was Selected Propeller was selected as a KER due to the following factors: ● Strategic fit with ELASTIC’s objectives, specifically low-latency orchestration and Wasm-native edge intelligence. ● Strong integration in both Demonstrators 1 and 2, where it powers secure data fabric services and confidential workload deployment. ● Concrete technical maturity with a public GitHub release and maintained documentation 60 . ● High reuse potential, particularly among IoT developers, embedded solution providers, and edge computing platforms. ● Clear exploitation commitment from AMA, who plans to support Propeller beyond the project via open-source and community-driven models. ● Market differentiation: Propeller fills a niche currently underserved by Kubernetesbased orchestrators or heavier service meshes. Demonstrator Relevance Propeller plays a central role in both of ELASTIC’s demonstrators: ● In Demonstrator 1, it enables orchestration of IoT services within the 6G data fabric, supporting low-latency execution at the edge. ● In Demonstrator 2, it integrates with TEEs to manage Wasm-based workloads, ensuring that workload execution benefits from the secure and attested environments provided by the underlying infrastructure. ● These applications validate Propeller’s technical feasibility and real-world relevance, making it a clear candidate for exploitation. 60 "Propeller," Propeller Documentation, Abstract Machines. Available: https://docs.propeller.abstractmachines.fr/ [accessed Aug. 10, 2025]. ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 87 - August 31, 2025 IP Background & TRL Propeller is developed by AMA and builds on prior IP, particularly AMA’s experience with embedded communication platforms. While initially at TRL1, Propeller is progressing toward TRL4, with demonstrator integration and external adoption pathways in development. Preliminary Value and Exploitation Potential Customer Pain Points Addressed: ● Inability to orchestrate workloads on microcontrollers or constrained IoT nodes. ● High resource overhead of Kubernetes and container-based orchestrators. ● Fragmented edge orchestration strategies across cloud, fog, and device layers. ● Lack of lightweight orchestration solutions that can integrate with TEEs for short-lived, event-driven workloads. Benefits Delivered: ● Low-footprint, Wasm-native orchestration deployable on MCUs and embedded RTOS. ● Unified deployment model from cloud to edge. ● Compatibility with secure execution contexts for sensitive workloads.. ● Reduced time and operational complexity in managing edge services. Target Audiences: ● IoT developers and edge solution providers. ● System integrators in industrial automation, smart cities, transport, and utilities. ● Research institutions and open-source communities working on Wasm and embedded AI. Preliminary Exploitation Outlook: ● Open-source core with Apache 2.0 license. ● Optional monetisation via enterprise support, integration, or dual licensing. ● Exploitation via community channels (e.g., GitHub), workshops, technical outreach, and possible collaboration with standardisation bodies (e.g., LF Edge, CNCF Wasm WG). Risks and Mitigation Challenges: ● Market unfamiliarity with Wasm in embedded systems. ● Resistance from enterprises tied to Kubernetes-based ecosystems. ● Lack of standardised tooling for Wasm on embedded devices. Mitigation Strategies: ● Open-source release and active community engagement. ● Integration with ELASTIC demonstrators as reference deployments. ● Outreach to embedded and RTOS communities. ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 88 - August 31, 2025 ● Possible future Kubernetes integration via a lightweight operator concept. 5.3.4 KER #4: WebAssembly Platform for Distributed Trusted Systems Overview This KER introduces a full-stack WebAssembly (Wasm) platform designed for building trusted, efficient, and portable distributed systems. It combines secure orchestration, runtime optimisation, low-latency communication, policy enforcement, and hardware abstraction into a cohesive framework. This WebAssembly platform is designed to operate across heterogeneous infrastructures - from cloud environments to constrained edge and embedded devices - providing the necessary building blocks for scalable, lightweight, and secure workloads. It integrates orchestration, system introspection, runtime security, and communication acceleration into a modular toolkit — including a Kubernetes-free Wasm orchestrator, resource-efficient operator execution, secure hardware abstraction, accelerated microservice communication, and static trust verification tooling. The platform demonstrates how Wasmbased architectures can replace heavier container-based stacks across edge-to-cloud infrastructures. In addition, the use of Wasm ensures that deployed systems can be updated and maintained with minimal disruption, a critical capability for infrastructures that must remain operational over multi-decade support periods. Why this KER was Selected This KER was selected due to its transformative potential in enabling secure, high-performance, and portable execution of distributed applications using Wasm - a core enabler for cloud-native and edge-native computing. The platform: ● Aligns with ELASTIC’s ambition to pioneer next-generation, trusted orchestration for 6G and IoT services. ● Promotes integration across software and hardware boundaries through WASI-based standardisation. ● Opens new exploitation pathways for high-performance workloads in microcontrollerclass and latency-sensitive environments. ● Provides a forward-looking alternative to monolithic container runtimes for edge-native distributed computing. Demonstrator Relevance In Demonstrator 1, the platform is deployed to orchestrate secure and high-performance applications across factories. It leverages Wasm’s compact runtime model to execute lowlatency microservices and enables resource-constrained devices to participate in distributed systems with workload-level isolation and trust. Included Components and Contribution Summary ● Propeller Orchestrator (AMA) ● Wasm-operator (IMEC) ● WasmHAL SDK and Runtime Extensions (IMEC) ● WASI Security (IMEC) ● Static Analysis of Interaction Between Wasm Modules (AAL) ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 89 - August 31, 2025 ● Accelerated Microservices Interconnection (POLITO) ● eBPF Distributed State Synchronisation (POLITO) Preliminary Value This KER enables the next generation of secure, low-overhead, cloud-to-edge distributed applications. It offers: ● Developers and infrastructure providers an open, standards-aligned platform to execute Wasm workloads securely on a wide range of devices. ● IoT and edge system integrators a lightweight orchestration layer that removes the need for Kubernetes. ● Cloud-native researchers and open-source contributors a foundation for building trusted WebAssembly-native systems. 5.3.5 KER #5: Confidential Computing, Security and Privacy Toolkit Overview This KER brings together a set of interoperable components that collectively provide a robust toolkit for Confidential Computing, targeting secure workload execution, attestation, policy enforcement, encryption, and trusted orchestration across edge and cloud environments. The toolkit offers foundational capabilities to manage TEEs throughout their lifecycle, ensuring workload confidentiality, integrity, security and verifiability. It includes runtime agents, security orchestrators, attestation platforms, key broker services, and secure workload migration protocols — enabling full-stack trust across heterogeneous infrastructures. Developed across multiple ELASTIC WPs and validated in both demonstrators, this KER is one of the most integrated and cross-functional results of the project. Why this KER was Selected This KER was selected due to its central role in enabling secure orchestration, workload trust, and data protection across edge and cloud environments - a key objective of ELASTIC. Confidential Computing is a rapidly emerging field with growing relevance in both industry and research, especially for regulated sectors and multi-tenant infrastructures. The KER consolidates critical project outputs into a reusable security toolkit, demonstrating: ● Strong integration across WP1, WP2, WP3, and WP4, including both demonstrators. ● Alignment with ELASTIC's vision of trusted, interoperable orchestration. ● Direct relevance to secure migration, secure public cloud operation, policy enforcement, and runtime trust. ● High potential for adoption in evolving Confidential Computing ecosystems. Demonstrator Relevance ● In Demonstrator 1, the toolkit is used to enforce policy-based orchestration and encryption of WASM workloads at rest via secure enclaves and hardware roots of trust. ● In Demonstrator 2, it enables remote attestation, key broker services, and secure workload migration from on-premise infrastructure to secure operation in public cloud environments, validating both runtime trust and data confidentiality. ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 96 - August 31, 2025 Zenodo, 30 poster downloads, 829 roll-up banner downloads, and 69 brochure downloads were recorded, bringing the total number of digitally distributed promotional materials to 928. These digital versions serve as an environmentally friendly complement to physical distribution and will continue to be shared through events, conferences, and partner networks. (Section 2.7) DEC-KPI-26 In progress No. of slide decks shared ≥ 3 Prepare and share at least three project-related slide decks So far, one general PowerPoint presentation has been created67. Additional slide decks will be developed as the project progresses, incorporating infographics, data, and key messages for use at events, meetings, and dissemination activities. DEC-KPI-27 In progress No. of short videos produced ≥ 2 Produce and publish at least two short videos during the project duration One short video has been produced68 and shared to support dissemination of project developments. Additional videos are planned to further showcase outcomes and increase visibility across dissemination channels. (Section 2.5.1) DEC-KPI-28 Achieved Project logo: 1; Templates (deliverables, milestones, presentations, posters): ≥ 4 Develop and share a project logo and at least four templates The project has successfully delivered 1 logo and 6 templates: PowerPoint, deliverable, quarterly technical progress report, cost claim, technical deliverable review sheet, and a poster template (under preparation). These templates support uniform communication and reporting across project outputs. (Section 2.9) 67 https://zenodo.org/records/15205868 68 https://www.youtube.com/watch?v=WBZHgk9d3SU ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 97 - August 31, 2025 7 Conclusion and Next Steps D6.2 provides a record of the progress achieved during the first 18 months of ELASTIC in the areas of communication, dissemination, standardisation, and exploitation (WP6). The deliverable shows how the consortium has translated the plans set out in D6.1 into concrete activities, including the establishment of a strong online presence, the production of communication materials, the organisation of campaigns and a webinar, and contributions to open-source and standardisation bodies. These actions have helped to increase the visibility of the project, build engagement with stakeholders, and lay the foundation for knowledge sharing and uptake. The reporting also highlights measurable achievements against KPIs, such as growth in social media followers, production of newsletters and press releases, participation in events, and first steps in exploitation planning through the definition of preliminary KERs. Standardisation and open-source activities further demonstrate how the technical results of the project are already contributing to wider communities and ongoing initiatives. Looking ahead, the consortium will continue to expand these activities to support Objective 5 (O5) of the project: to facilitate 6G standardisation, exploitation, and dissemination of the developed isolation and orchestration technologies, while aligning with EU supply capabilities and opportunities in efficient, secure, and privacy-preserving service deployment. Next steps include: ● Scaling outreach through additional newsletters, press releases, and targeted campaigns. ● Continuing to update and expand the website and social media presence to ensure visibility across research, industry, and policy audiences. ● Organising further webinars, workshops, and joint events with other SNS JU projects to strengthen collaboration. ● Advancing standardisation engagement by evaluating opportunities for joint contributions and supporting partner participation in SDOs. ● Increasing open-source contributions and promoting adoption in developer communities. ● Refining the set of KERs and supporting their maturation with guidance and coaching to prepare for sustainability and uptake beyond the project’s lifetime.. Through these steps, ELASTIC will ensure that its communication and dissemination activities remain consistent with the overall objectives of WP6, continue to deliver value to stakeholders, and maximise the long-term impact of the project results. ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 98 - August 31, 2025 8 Annex I – Exploitation Analysis of ELASTIC Individual Components This annex provides a detailed exploitation analysis of the individual ELASTIC components, complementing the KERs discussed in the main body of the deliverable. Table 8: Federated Learning as a Service (FLaaS) - TID Name of Result Federated Learning as a Service (FLaaS) Partner Name TID Type of Result Software and system Associated WP, Task & Demonstrator WP4/T4.3, Demonstrator 1 Brief Description - what it does FLaaS is an existing software component providing Federated Learning (FL) as a service, allowing third-party applications to train collaborative machine learning models on IoT devices in a privacy-preserving manner. Within ELASTIC, FLaaS is being extended to support Split Learning (SL), enabling participation of resource-constrained devices by offloading part of the model training to more computationally-powerful devices. Specifically, the aim is to integrate SL with Trusted Execution Environments (TEEs) within FLaaS to enable secure execution and training in heterogeneous environments, further enhancing the privacy-preserving capabilities of FLaaS. Background IP Yes Current/ Expected TRL Current: TRL4 / Expected: TRL5 Use of IP/Result Exploitation Use Further R&D Projects Can it be Protected? Potentially IPR Protection Method Patent Customers/ Users/Target Audience 1. Different teams within Telefonica such as the Home AI team. 2. Venture builders for a potential spin-off Pains of customers/Users 1. Lack of accessible, secure FL/SL frameworks for resource-constrained IoT devices 2. Complexity and expertise required to deploy Federated or Split Learning at scale 3. Concerns around privacy and regulatory compliance when training ML models on edge data Benefit of Customers/Users 1. First solution combining Split Learning and TEEs 2. Enables secure and efficient ML model training with heterogeneous devices 3. Simplifies FL/SL usage for non-experts, lowering adoption barriers Target audience 1. Telefónica business units and technical teams such as the Home AI team 2. External enterprise customers through B2B offerings 3. Telefónica’s venture building initiatives for potential start-ups Business model Potentially a B2B model, e.g., through providing the training of an ML model through FLaaS for another business (e.g., a mobile application provider) Exploitation channels 1. Industry alliances and working groups 2. Collaborative R&D projects and open-source communities 3. Telefónica innovation units and internal stakeholders Risks & Challenges Market PositionDefine the place the product/service aims to occupy in the market, e.g., is it a premium offering, a budget solution, or a niche product? The component aims to provide an accessible solution for ML model training for heterogeneous devices in a secure and privacy-preserving distributed manner. Major companies like Google are already employing such solutions, but only internally. The aim of FLaaS is to make such solutions accessible to a much broader audience by offering it as a service. ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 99 - August 31, 2025 Deployment Barriers 1. Original developers of FLaaS are no longer working at Telefonica. 2. Use of Wasm brings its own challenges. 3. Increase TRL since product development teams in Telefonica need to be sufficiently interested for market adoption. 4. Scalability. Other Challenges 1. Potential mismatch with short-term market needs 2. Funding continuity for post-project development 3. Limited infrastructure for large-scale validation Mitigation Measures 1. Develop a new Federated Learning and Split Learning framework, so that we do not need to rely on the FLaaS system. 2. Use existing frameworks such as Flower AI to integrate our new technologies. 3. Incorporate this technology into new project proposals to continue its funding. Other Solutions (Current State of the Art) 1. Flower AI supports FL, but lacks SL, Wasm, and TEE integration. 2. Some research exists on FL with Wasm or TEEs, but not both. 3. SL approaches are mostly heuristic-based, without theoretical guarantees. Overall, no existing platform offers SL and TEEs in a unified solution. Table 9: Wasm-operator - IMEC Name of Result Wasm-operator Partner Name IMEC Type of Result Software component Associated WP, Task & Demonstrator T2.1, T2.4, Demonstrator 1 Brief Description - what it does Software runtime for executing Kubernetes operators as event-based, serverless functions in WebAssembly. It enables reduced memory usage and overhead by running multiple operators in a shared Wasm runtime, swapping inactive operators to disk, and leveraging Rust for more efficient memory management. The framework supports compatibility with existing kube-rs-based operators. Background IP Yes - This is a continuation of our open source framework that already existed before this project. Current/ Expected TRL Current: TRL3 / Expected: TRL4 Use of IP/Result Exploitation Use Research Services Can it be Protected? No IPR Protection Method N/A Customers/ Users/Target Audience 1. Cloud service and IoT providers 2. Cloud and IoT consulting companies 3. Device manufactures and IIoT manufacturers Pains of customers/Users 1. High memory use on low-resource edge/IoT devices, limiting edge deployments. 2. Large RAM overhead in multi-cluster Kubernetes setups, raising costs and complexity. 3. Inefficient resource use due to always-on operators even when idle. 4. Limited flexibility to adapt operators to constrained environments. Benefit of Customers/Users 1. Significantly reduced memory usage per Kubernetes operator 2. Improved scalability in resource-constrained environments 3. Faster operator startup with predictive scheduling 4. Seamless compatibility with existing Kubernetes operator ecosystem Target audience 1. Telecom operators deploying edge/cloud-native infrastructure 2. Industrial IoT solution providers using Kubernetes on constrained hardware 3. Smart edge computing vendors managing distributed clusters 4. Cloud-native platform developers optimising Kubernetes for low-resource environments Business model We do not intend to engage in direct commercialisation of this product. Instead, we foresee impact in the following ways. ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 100 - August 31, 2025 1. Open-source dissemination of implemented components to encourage broad adoption, collaborative innovation, and further development within industrial and academic communities. 2. Research collaborations and strategic partnerships with industry stakeholders, aimed at integrating the developed solution into real-world network environments. The go-to-market strategy prioritises visibility and stakeholder engagement through: 1. Academic and industrial dissemination activities, 2. Participation in EU initiatives and demonstrator projects, 3. Active involvement in cybersecurity clusters and innovation communities. Exploitation channels 1. Integration via research and industry technology transfer collaborations 2. Open-source communities and repositories 3. Demonstration, training, consulting and technical support services 4. Standardisation and certification directions Risks & Challenges Market PositionDefine the place the product/service aims to occupy in the market, e.g., is it a premium offering, a budget solution, or a niche product? Niche enabling technology designed to enhance Kubernetes efficiency in low-resource or large-scale deployments. Positioned as an open-source performance and footprint optimisation layer for Kubernetes control plane extensions. Deployment Barriers 1. It currently only works for operators written using kube-rs. 2. It currently only works for operators that can be compiled to WebAssembly using our patched kube-rs. Other Challenges 1. Lack of (de-facto) standardisation 2. Risk of another solution gaining widespread adoption. Mitigation Measures 1. Broadly disseminate the framework to ensure widest possible reach. 2. Present the framework to relevant Kubernetes working groups to gather mindshare. Other Solutions (Current State of the Art) 1. No direct competitor offering operator-level memory optimisation using WebAssembly. 2. Complementary solutions like Feather and KubeEdge optimise Kubernetes for edge devices, but focus on lightweight Kubernetes distributions rather than reducing controlplane plugin overhead. 3. Some projects offer Wasm-based plugins (e.g., for schedulers or policy engines like Open Policy Agent), but not full operator support. Table 10: Light-weight Security Orchestrator for Edge Devices - THS Name of Result Light-weight Security orchestrator for Edge devices Partner Name THS Type of Result Software Associated WP, Task & Demonstrator WP3/T3.4, Demonstrator 1 Brief Description - what it does The lightweight orchestration agent manages and deploys WebAssembly (WASM) security functions based on customisable security policies and SSLAs, tailored to the needs of verticals across edge and cloud environments. It uses attestation to ensure the trustworthiness of the WASM runtime before deploying workloads via orchestration frameworks like Kubernetes. Drawing from a catalog of pre-evaluated security enablers, the agent continuously monitors workload behavior through telemetry and dynamically adapts orchestration to maintain policy compliance. This enables robust, real-time security enforcement even on resource-constrained edge devices. Background IP reuse of internal security policy management system, SSLA management solutions and existing heavyweight security orchestration frameworks from THALES Current/ Expected TRL Current: TRL2 / Expected: TRL4 Use of IP/Result ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 101 - August 31, 2025 Exploitation Use Further R&D Projects Can it be Protected? Yes IPR Protection Method Patent Customers/ Users/Target Audience 1. Telecom operators – supporting 5G/6G service security enforcement and SLA-driven protection of network functions. 2. Cloud and edge infrastructure providers – enabling secure and trusted deployment of services across heterogeneous, distributed environments. 3. Industrial automation vendors – addressing security and compliance needs in resource-constrained, high-reliability OT/IT systems. 4. Public sector and defence organisations – securing mission-critical systems with strong isolation, attestation, and policy-driven orchestration. Pains of customers/Users 1. Complexity and inefficiency in deploying and adapting security policies across dynamic environments 2. Insufficient trust and attestation capabilities at the edge 3. Lack of lightweight orchestration frameworks for constrained devices 4. Vendor lock-in and limited interoperability with modern formats like WASM Benefit of Customers/Users 1. Lightweight and modular orchestration, ideal for resource-limited edge devices 2. Real-time compliance with dynamic security policies, aligned with vertical-specific SSLAs 3. Platform-agnostic deployment via WASM, improving portability and reusability 4. Enhanced trust via attestation and TEE integration, reducing risk exposure Target audience 1. System architects, edge/cloud orchestrators 2. Security administrators, platform operators 3. OEMs and integrators building secure IoT/edge platforms Business model There are several possible Licensing options according to users and customers’ requirements that may include: - Perpetual Licenses – one-time fee for unlimited use within a specific deployment scope, often suited for large industrial or defence systems with long lifecycle requirements. - Subscription-based Licenses – recurring annual or monthly fees tied to usage metrics (e.g., number of deployed agents, edge nodes, or managed workloads), offering flexibility and predictability for telecom and cloud providers. - OEM/Embedded Licenses – tailored agreements for industrial vendors to embed the agent within their own products or services, enabling value-added security orchestration under their own brand. - Enterprise Licenses – customised packages for large organisations, including priority support, integration services, and access to advanced orchestration features and updates. Exploitation channels 1. Business lines of the various business units of Thales : THALES AVIONICS, THALES Alinea Space (TAS, Space Edge), Communications (SIX, NIS) 2. Partnerships through EU projects and ecosystem alliances 3. Technology licensing and standardisation contributions Risks & Challenges Market PositionDefine the place the product/service aims to occupy in the market, e.g., is it a premium offering, a budget solution, or a niche product? Niche, high-assurance solution for trusted orchestration in secure edge environments. Targets premium applications in telecom, defence, and industrial automation requiring verifiable runtime integrity and adaptive security. Deployment Barriers 1. Early-stage prototype 2. WASM-based orchestration is still emerging 3. Limited standardisation around policy formats and workload trustworthiness 4. Diverse hardware and OS platforms at the edge may limit portability Other Challenges 1. Need for cross-vertical policy abstraction models 2. Integration with legacy systems and non-WASM workloads 3. Real-time telemetry analysis at the edge 4. Balancing performance overhead with security compliance ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 102 - August 31, 2025 Mitigation Measures 1.1. Engage in pilot deployments with selected telecom or industrial partners 2. Contribute to WASM and orchestration standardisation bodies 3. Develop policy abstraction templates for main verticals 4. Build a library of trusted WASM functions to ease adoption Other Solutions (Current State of the Art) 1. Kubernetes with standard container orchestration (not optimised for TEE or WASM) 2. Confidential Computing orchestration frameworks (e.g., Enarx, Gramine) 3. Open Policy Agent (OPA) – widely used but not WASM-native or lightweight for edge 4. AWS Nitro Enclaves / Azure Trusted Launch – cloud-centric, not edge-optimised Table 11: Federated Learning Toolbox - ZEN Name of Result Federated Learning Toolbox Partner Name ZEN Type of Result WP4/T4.2 & T4.3, Demonstrator 1 Associated WP, Task & Demonstrator FL toolbox is a standalone or integrated cloud solution for orchestrated collaborative data analysis without central posting of the datasets, using a secure node and cloud infrastructure. Node receives a task from the server and (currently) executes it by downloading the requested Docker image, which is in process of being completely replaced with WebAssembly modules. The container accesses the local data through the node and executes ML algorithms with given parameters. The solution features optimal encrypted computation (MPC or HE), with a learning model saved onto the DLT for full traceability and guaranteed immutable auditing. Brief Description - what it does Yes – Based on ZEN’s existing FL infrastructure and orchestration expertise, including prior deployments in privacy-preserving analytics. ELASTIC enhances this with new capabilities including Wasm integration and advanced federated ML orchestration over constrained devices. Background IP Current: TRL3 / Expected: TRL4 Current/ Expected TRL WP4/T4.2 & T4.3, Demonstrator 1 Use of IP/Result Exploitation Use Direct Commercialisation Can it be Protected? Potentially IPR Protection Method Copyright Customers/ Users/Target Audience 1. Smart manufacturing and cross-facility production optimisation 2. Healthcare 3. Research and e-government sectors benefitting from distributed analytics over multiple confidential datasets 4. Logistics and supply chain 5. Agri-food and environment (improving disease/pest or hazards prediction and control) Pains of customers/Users 1. Need for secure unified federated data analytics and ML/AI (particularly training the models) over different confidential or non-proprietary datasets without exposing or compromising sensitive information 2. Poor performance and orchestration issues in the execution of the above, especially with demanding workloads/algorithms and/or over a high number or diversity of encompassed datasets Benefit of Customers/Users 1. Enabling secure unified federated data analytics and ML/AI over different confidential or non-proprietary datasets without exposing or compromising sensitive information 2. Acceptable performance level and smooth orchestration in the execution of the above, especially with demanding workloads/algorithms and/or over a high number or diversity of encompassed datasets Target audience Technology and solution providers (to specific verticals stated above, and in general, ICT cloud service vendors, cybersecurity asset providers), technical, data science/analytics infrastructure and operations managers and administrators. Business model Monetisation envisioned through (but not limited to) periodor throughput-based service charges (such as monthly fees per user, or per each API call when accessing encrypted ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 103 - August 31, 2025 datasets), also tailored custom deployments (integrated with existing core or legacy systems like ERP), and as a component included in other Zentrix solutions. Exploitation channels - Industry and open-source communities, consortia and alliances - Special interest or task groups - Trade fairs and projects on applied ICT in specific verticals listed above - Potentially standardisation Risks & Challenges Market PositionDefine the place the product/service aims to occupy in the market, e.g., is it a premium offering, a budget solution, or a niche product? A niche, high-assurance federated learning orchestration tool optimised for edge performance and strict data privacy/compliance requirements. Positioned as a value-added service within premium analytics or secure data platforms. Deployment Barriers 1. Complexity of integrating secure FL into heterogeneous existing infrastructures 2. Technical maturity and awareness gap for Wasm-enabled FL in edge environments 3. Cost and resource constraints in smaller organisations or institutions 4. Initial performance tuning needed depending on workload types and encryption levels Other Challenges 1. Need to build trust and understanding around FL in conservative sectors (e.g., healthcare, government) 2. Fragmented landscape of FL frameworks and ML toolchains 3. Limited support for encrypted AI/ML computation in lightweight formats (e.g., TensorFlow Lite with HE/MPC) 4. Resource-intensive regulatory compliance obligations (e.g., GDPR, HIPAA) Mitigation Measures 1. Provide end-to-end pilot deployments to demonstrate impact and performance 2. Align with ELASTIC ecosystem components and integrate open standards (e.g., Wasm runtime APIs) 3. Partner with trusted industry players and testbeds to build credibility 4. Develop training and onboarding packages for system integrators and customers Other Solutions (Current State of the Art) 1. Freely available FL frameworks offering out-of-the-box advanced functionalities (e.g. Flower, PySyft, OpenFL) - focused or general-purpose but not Wasm/edge-optimised 2. Emerging specialised startups like Zama (www.zama.ai) in Europe 3. Academic research paper - Web-Centric Federated Learning over the Cloud-Edge Continuum Leveraging ONNX and WASM (Reference: https://ieeexplore.ieee.org/document/10733614), but it uses browser as the main runtime, but lacks support for edge deployments. 4. Nvidia Clara FL, focused on healthcare with hardware dependency Table 12: TEE Software Management Agent - UVC Name of Result TEE Software Management Agent Partner Name UVC Type of Result Software Associated WP, Task & Demonstrator WP3/T3.2 & WP2/T2.3, T2.4 Demonstrator 1 & 2 Brief Description - what it does The TEE Agent ensures secure processing of sensitive data within Trusted Execution Environments (TEEs). It validates environment integrity through remote attestation, manages workloads securely, handles cryptographic operations, and enforces fine-grained access control policies. Its role is essential in safeguarding data throughout its lifecycle— from ingestion to storage and processing—within the secure enclave. Background IP Yes – Internal UVC IP used for workload management in TEE and secure key handling Current/ Expected TRL Current: TRL2 / Expected: TRL3 Use of IP/Result Exploitation Use Further R&D Projects Can it be Protected? Potentially ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 104 - August 31, 2025 IPR Protection Method Copyright Customers/ Users/Target Audience 1. Edge and Cloud Orchestrator providers 2. Industrial IoT platform vendors 3. Security infrastructure integrators 4. Research institutions focusing on TEE/Confidential Computing Pains of customers/Users 1. Lack of trust in execution environments 2. Exposure of sensitive data 3. Limited visibility into workload security 4. Lack of seamless integration with orchestrators Benefit of Customers/Users 1. Trusted and verifiable workload execution 2. Secure enclave I/O handling 3. Integrated monitoring and attestation 4. Lightweight component adaptable across platforms Target audience Technical: Cloud/Edge platform developers, TEE/Confidential Computing infrastructure providers Business: Critical infrastructure operators (e.g., telecom, smart manufacturing, health), cybersecurity vendors Business model Open-source base with optional commercial extensions or support packages. Potential integration into existing commercial offerings in the trusted computing space. Exploitation channels Open source, Industry alliances (e.g., Confidential Computing Consortium), Technical publications, Developer outreach via workshops & hackathons Risks & Challenges Market PositionDefine the place the product/service aims to occupy in the market, e.g., is it a premium offering, a budget solution, or a niche product? The TEE Software Management Agent is positioned as a niche and high-trust solution for managing the secure lifecycle of workloads within Trusted Execution Environments. It targets specialised users requiring robust, verifiable security guarantees in sensitive edge and cloud computing scenarios. Deployment Barriers 1. Limited awareness of secure workload lifecycle management 2. Complexity of integrating with existing orchestrators 3. Performance trade-offs in secure enclaves 4. Compatibility across diverse TEE implementations Other Challenges 1. Limited internal funding beyond project lifecycle 2. Market fragmentation in TEE technologies 3. Need for coordinated standardisation 4. Limited in-house business development capacity Mitigation Measures 1. Reuse existing open standards and interfaces 2. Align with ELASTIC components for compatibility 3. Disseminate through academic and industry channels 4. Seek collaboration with larger vendors and alliances Other Solutions (Current State of the Art) 1. Intel SGX SDK 2. Microsoft Open Enclave SDK 3. SCONE 4. Gramine 5. Enarx 6. Opaque Table 13: Reliable enclave migration protocols - AAL Name of Result Reliable enclave migration protocols Partner Name AAL Type of Result Methodologies, software Associated WP, Task & Demonstrator WP1, T1.2 Demonstrator 2 ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 105 - August 31, 2025 Brief Description - what it does This component offers secure protocols for reliable migration of sensitive resources between Trusted Execution Environments (TEEs). It ensures atomic migration—either fully completing or safely aborting—preventing data loss or duplication even under network failures or attacks. Using distributed consensus and fair-exchange techniques, the protocols adapt to various scenarios and integrate into a Wasm framework for smooth orchestration, supporting secure and fault-tolerant enclave migration in cloud and edge systems. Background IP Builds on prior work in fair-exchange and distributed protocols for enclave migration, notably Geisler and Gunn (2022), adapted for secure, reliable use in TEE environments. Current/ Expected TRL Current: TRL3 / Expected: TRL4 Use of IP/Result Exploitation Use Indirect Licensing through Vendor Can it be Protected? Potentially IPR Protection Method Copyright Customers/ Users/Target Audience 1. Cloud service providers 2. Edge computing platform operators 3. Confidential computing infrastructure developers 4. Security-critical application providers Pains of customers/Users 1. Risk of resource loss or duplication during migration due to network disruptions or malicious interference 2. Lack of reliable, TEE-compatible migration protocols with strong security guarantees 3. Limited support for fallback or recovery mechanisms in current solutions 4. Difficulty integrating secure migration into existing orchestration frameworks Benefit of Customers/Users 1. Enables secure migration of sensitive resources between TEEs without compromising integrity or availability 2. Provides recovery guarantees even under adverse network conditions or partial failures 3. Reduces the risk of data duplication or loss during migration 4. Facilitates compliance with security and reliability requirements in cloud and edge environments Target audience 1. Cloud service providers 2. Platform orchestrator vendors 3. Confidential computing solution providers 4. Researchers in distributed systems and trusted execution Business model Open source distribution model, enabling broad adoption and community-driven improvements. Designed for indirect exploitation by integration into orchestration platforms, cloud stacks, or confidential computing toolchains, rather than through direct monetisation. Exploitation channels 1. Public code repositories (e.g., GitHub, GitLab) to release and maintain software openly. 2. Collaboration with open-source communities to co-develop and improve projects. 3. Open licensing models (e.g., Apache 2.0, MIT, CC0) that encourage adoption and contribution. 4. Integration into wider open ecosystems (e.g., Linux Foundation projects, CNCF). 5. Promotion through academic publications, workshops, and conferences to increase visibility. 6. Industry partnerships that adopt and support the open-source software as part of their offerings. 7. Participation in open innovation networks and consortiums to align project goals with community needs. Risks & Challenges Market PositionDefine the place the product/service aims to occupy in the market, e.g., is it a premium offering, a budget solution, or a niche product? The reliable enclave migration protocols aim to occupy a niche product position in the market, targeting securityand safety-critical environments such as cloud and edge computing platforms where trusted execution and secure migration are essential. It focuses on providing strong security guarantees that are not addressed by standard migration solutions, positioning itself as a specialised, high-assurance technology rather than a general-purpose or budget solution. Deployment Barriers 1. Increased latency and resource overhead due to additional confirmation steps compared to conventional migration protocols. ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 112 - August 31, 2025 Type of Result Software Associated WP, Task & Demonstrator WP1/T1.2, WP4/T4.3 Brief Description - what it does This component automates the generation of Mandatory Access Control (MAC) profiles for WebAssembly workloads running on container platforms. By analysing the specific resource access needs (filesystem, network, syscalls) of each Wasm module, it creates restrictive access profiles that minimise privileges, thus reducing attack surfaces. It integrates with the Wasm runtime and execution platform to generate these profiles automatically during testing, enabling stronger runtime security and easier enforcement of least-privilege policies. Background IP Yes Current/ Expected TRL Current: TRL3 / Expected: TRL4 Use of IP/Result Exploitation Use Spin-off Company Can it be Protected? Potentially IPR Protection Method Patent Customers/ Users/Target Audience 1. Software infrastructure providers 2. SaaS providers 3. Operators 4. Cloud and edge platform providers deploying Wasm workloads 5. Researchers focusing on Wasm security Pains of customers/Users 1. Integration cost/troubles 2. Risk of denying benign Wasm applications 3. Non compatible runtime Benefit of Customers/Users 1. Higher Wasm security level 2. Less configuration is needed 3. Automates privilege profiling, reducing human error 4. Enhances security by minimising Wasm workload privileges 5. Facilitates compliance and security auditing Target audience 1. WebAssembly application developers 2. Wasm runtime developers 3. IT security managers 4. Cloud and edge platform operators responsible for security policies Business model Software Licensing: Offer a per-node licensing model where customers pay a recurring fee based on the number of nodes (servers or runtime instances) where the software is deployed. This aligns costs with usage and scales with customer needs. Exploitation channels 1. Commercialisation via a spin-off company originating from Lund University, responsible for further development, marketing, and sales. 2. Publication of research articles and technical reports leveraging Lund University’s academic network to build credibility and attract partners. Risks & Challenges Market PositionDefine the place the product/service aims to occupy in the market, e.g., is it a premium offering, a budget solution, or a niche product? The product targets a niche market as a specialised security solution for WebAssembly runtimes, focusing on advanced automatic access control profiling for high-security needs. Deployment Barriers 1. Early trials and lots of research and development left to reach a mature product 2. The needed Wasm policy framework is also in a very early stage 3. Extensive testing with several different Wasm workloads is needed to ensure the policy engine quality Other Challenges 1. Ensuring compatibility with various Wasm runtimes. 2. Encouraging user adoption and proper use. Mitigation Measures 1. Collaborate with Wasm runtime developers for compatibility. 2. Optimise the profiling engine for low overhead. ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 113 - August 31, 2025 3. Provide clear documentation and user support. 4. Continuously update the tool to address new threats. Other Solutions (Current State of the Art) 1. No existing tools specifically for automatic MAC profiling of Wasm workloads. 2. Manual profiling methods for Docker containers (e.g., AppArmor, SELinux). 3. General access control frameworks for traditional applications. 4. Emerging research on Wasm security but no mature commercial tools yet. Table 19: WasmHAL Hardware SDK, interfaces, and runtime extensions for securely connecting Wasm applications to hardware across platforms - IMEC Name of Result WasmHAL Hardware SDK, interfaces, and runtime extensions for securely connecting Wasm applications to hardware across platforms Partner Name IMEC Type of Result Software and Standards Associated WP, Task & Demonstrator T2.1, T2.4, T4.1, Demonstrator 1 Brief Description - what it does This component provides standardised APIs and runtime extensions that enable WebAssembly applications to securely access and interact with external hardware interfaces such as USB, I2C, GPIO, and others across different platforms. It abstracts hardware specifics, allowing consistent and portable device driver execution within the WebAssembly runtime, simplifying development while ensuring strong security and isolation. Background IP We had limited experience with standardising WASI interfaces when the project started. Current/ Expected TRL Current: TRL2 / Expected: TRL4 Use of IP/Result Exploitation Use New Standard Can it be Protected? No IPR Protection Method N/A Customers/ Users/Target Audience 1. Vendors of microcontrollers 2. Vendors of (I)IoT devices and devices that contain microcontrollers 3. Vendors of embedded Linux devices and devices that contain embedded Linux devices. Pains of customers/Users 1. Most microcontrollers are a pain to update over a multi-decade long support period. 2. WebAssembly does not make it possible to access external hardware. 3. Most microcontroller are very limited in the programming languages and toolchains they support. Benefit of Customers/Users 1. Simplifies long-term firmware updates for microcontrollers by enabling WebAssembly as a flexible runtime 2. Provides a standardised hardware abstraction layer (HAL) for uniform, OS-independent hardware access 3. Enables use of modern programming languages and toolchains on legacy and resourceconstrained devices Target audience 1. Vendors of microcontrollers 2. Vendors of (I)IoT devices and devices that contain microcontrollers 3. Vendors of embedded Linux devices and devices that contain embedded Linux devices. Business model We do not intend to engage in direct commercialisation of this product. Instead, we foresee impact in the following ways. 1. Open-source dissemination of implemented components to encourage broad adoption, collaborative innovation, and further development within industrial and academic communities. 2. Research collaborations and strategic partnerships with industry stakeholders, aimed at integrating the developed solution into real-world network environments. The go-to-market strategy prioritises visibility and stakeholder engagement through: 1. Academic and industrial dissemination activities, ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 114 - August 31, 2025 2. Participation in EU initiatives and demonstrator projects, 3. Active involvement in cybersecurity clusters and innovation communities. Exploitation channels 1. Integration via research and industry technology transfer collaborations 2. Open-source communities and repositories 3. Demonstration, training, consulting and technical support services 4. Standardisation and certification directions Risks & Challenges Market PositionDefine the place the product/service aims to occupy in the market, e.g., is it a premium offering, a budget solution, or a niche product? The WasmHAL SDK aims to be a foundational technology enabling a new class of portable, secure, and standardised WebAssembly-based hardware interfaces, positioned as a niche but strategic enabler in embedded and IoT ecosystems. Deployment Barriers 1. The code is not yet upstreamed and currently only supported on a limited number of runtimes, primarily Wasmtime, making adoption challenging. 2. Customer applications must be compatible with WebAssembly and WASI, requiring adjustments in build and deployment workflows. 3. Existing client applications may need modification to replace OS-specific hardware APIs with the new standardised WebAssembly HAL APIs, which could involve development overhead. Other Challenges 1. Ensuring low-latency and real-time performance for hardware access across diverse embedded and IoT platforms. 2. Achieving broad runtime support and community adoption to avoid fragmentation. 3. Keeping security and access control mechanisms robust while maintaining usability and ease of integration. 4. Aligning with ongoing WASI standardisation efforts to ensure long-term compatibility and maintainability. Mitigation Measures 1. Ongoing discussions with WAMR maintainers to include WasmHAL APIs in the upcoming Long-Term Support (LTS) release to improve availability and usability 2. Broad dissemination and engagement with toolchain and compiler developers to ensure compatibility and support for WasmHAL APIs 3. Continuous participation in community forums and standards groups to drive adoption and ecosystem maturity Other Solutions (Current State of the Art) 1. Native hardware abstraction layers such as embedded_hal (Rust ecosystem) and vendorspecific HALs 2. Limited WASI proposals focusing mainly on cloud-centric APIs without hardware connectivity 3. Specialised runtime extensions or frameworks like WARDuino (Arduino-specific), Aerogel (access control framework), WiProg (IoT programming framework), WAIT (lightweight WASM runtime), and Wasmachine (bare-metal WASM OS) which address subsets of hardware or security needs but lack portability or broad standardisation Table 20: Static eBPF code security Analyser - POLITO Name of Result Static eBPF code security Analyser Partner Name POLITO Type of Result software Associated WP, Task & Demonstrator WP1/T1.3, T1.4 - Demonstrator 1 Brief Description - what it does The static eBPF code security analyser is a software tool that can analyse eBPF source C code and spot the security vulnerabilities that prevent the code from being accepted by the verifier, providing the developer with clear-to-understand and early error messages, contrary to what happens currently. A second goal of the tool is also to provide the developer with fix suggestions related to the original C source code, so making the fixing of the code easier and faster for the programmer. Background IP None ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 115 - August 31, 2025 Current/ Expected TRL Current: TRL2 / Expected: TRL3 Use of IP/Result Exploitation Use Research Services Can it be Protected? Yes IPR Protection Method Copyright Customers/ Users/Target Audience 1. eBPF developers seeking improved tools for early error detection and code security analysis. 2. Companies and organisations developing or deploying eBPF-based applications and solutions across industries such as networking, cybersecurity, and cloud infrastructure. 3. Open-source communities and contributors involved in the Linux kernel and eBPF ecosystem. 4. Research institutions and academic groups working on eBPF-related projects or security analysis tools. Pains of customers/Users 1. Difficulty understanding and fixing eBPF verifier errors due to their late detection and complex bytecode-oriented messages 2. Lack of tooling for early, source-level detection of vulnerabilities in eBPF code 3. Inefficient debugging processes that increase development time and risk of security flaws Benefit of Customers/Users 1. Early detection of security vulnerabilities at compile time with clear, actionable feedback 2. Enhanced developer experience through understandable error reporting and fix guidance 3. Increased productivity and security in eBPF code development 4. Reduced time-to-debug and lower risk of deploying insecure code Target audience 1. Individual eBPF code developers aiming to enhance productivity and code quality. 2. Industrial and commercial enterprises integrating eBPF technologies into their products or services. 3. Linux and eBPF community members, including maintainers and contributors. 4. Research and academic stakeholders interested in eBPF development and security innovation. Business model POLITO is a public Technical University. For this reason, it is not pursuing direct commercial exploitation of its research products. Rather, POLITO's mission is to disseminate and transfer its knowledge and research products to other stakeholders interested in using or building products based on them. At the same time, POLITO aims to get funding for its activities by participating in funded research programs and collaborations with industrial partners and to improve its external visibility. POLITO's exploitation goals related to this component will be pursued mainly through the following activities: 1. The open-source release of the software, to encourage adoption, collaboration, and further development by industry and research communities. 2. The promotion of collaborations with existing industrial stakeholders interested in using or exploiting the component, or of new spinoffs for the commercial exploitation of the component. 3. The capitalisation of the gained experience and its use in participating in forthcoming funded project proposals, dissemination, and technology transfer initiatives. Exploitation channels 1. Open-source software repositories and projects to maximise visibility and communitydriven enhancement. 2. Engagement with Linux and eBPF ecosystem communities to integrate the tool into relevant workflows and gain early adopters. 3. Strategic partnerships and collaborations with industrial actors interested in eBPF technology and security tooling. 4. Participation in funded research programs to further develop, validate, and extend the capabilities of the analyser. Risks & Challenges Market PositionDefine the place the product/service aims to occupy in the market, e.g., is it a premium offering, a The Static eBPF Code Security Analyser targets a niche but critical segment within eBPF code development: advanced, security-aware developers and organisations requiring robust, efficient tools for ensuring code safety before deployment. Its focus on early error detection and actionable fixes differentiates it from existing solutions. ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 116 - August 31, 2025 budget solution, or a niche product? Deployment Barriers 1. Frequent and potentially disruptive updates to the Linux eBPF verifier and related toolchains may necessitate ongoing maintenance and timely adaptation of the analyser. 2. Limited integration with existing developer toolchains and IDEs might slow adoption among developers accustomed to established workflows. Other Challenges 1. Difficulty in identifying and engaging relevant industry stakeholders or commercial partners interested in adopting or contributing to the component, especially given the academic origin of the tool. 3. Competition from alternative tools or approaches that may already be embedded in certain development pipelines or appear in the near future. 4. Ensuring sustained community involvement and contributions to maintain and evolve the open-source project post-release. Mitigation Measures 1. Designing the analyser to be as independent as possible from verifier internals and specific toolchain versions to ease maintenance. 2. Active dissemination and promotion at conferences, workshops, and in open-source communities to raise awareness and gather feedback. 3. Seeking partnerships with industry leaders and research groups to ensure alignment with real-world needs and sustainable development. Other Solutions (Current State of the Art) 1. eBPF development approaches based on safe programming languages like Rust offer safety guarantees but may incur performance overheads and limit flexibility compared to C-based eBPF development. 2. Existing kernel verifier enhancements and formal verification methods primarily operate on bytecode level and lack early source-level feedback and fix suggestions. 3. Static analysis tools for C in general do exist, but they are not tailored to eBPF’s specific constraints and verifier requirements. 4. Commercial proprietary tools for kernel and embedded development provide some static analysis features but are often costly and not specialised for eBPF security challenges. Table 21: Static analysis of interaction between Wasm modules - AAL Name of Result Static analysis of interaction between Wasm modules Partner Name AAL Type of Result Software Associated WP, Task & Demonstrator WP1, T1.4 & T3.2 & T3.3, Demonstrator 1 Brief Description - what it does This result develops static analysis tools to examine interactions between multiple Wasm modules before runtime, reducing the need for costly dynamic checks and improving performance. It supports the Wasm Component Model by identifying the composition of component-based applications in a way that is independent of whether they are deployed as a single unit, as several components on a single system, or as a fully-distributed application. Additionally, it enhances attestation capabilities for distributed serverless applications by enabling verification of multi-module, multi-host trustworthiness—overcoming limitations of current TEEs that only attest single modules. The solution extends Wasm runtimes and introduces new metadata and trust frameworks to ensure secure, efficient, and flexible Wasm-based applications. Background IP No Current/ Expected TRL Current: TRL1 / Expected: TRL2 Use of IP/Result Exploitation Use Indirect Licensing through Vendor Can it be Protected? Yes IPR Protection Method Copyright Customers/ Users/Target Audience 1. Application framework developers (e.g., WasmCloud, Kubernetes) 2. Cloud service providers deploying serverless or microservice applications ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 117 - August 31, 2025 3. Developers of confidential computing and trusted execution environments (TEEs) 4. Researchers and tool creators focused on Wasm security and verification Pains of customers/Users 1. TEEs currently support attestation only for code running on a single host, limiting trust guarantees for distributed or multi-component applications. 2. This gap forces developers to invest significant effort and expertise to manually ensure end-to-end security and trustworthiness across complex distributed systems. 3. Lack of scalable and automated attestation for composite applications hinders adoption of TEEs in cloud-native, serverless, or microservice environments. Benefit of Customers/Users 1. Enables comprehensive attestation and trust verification for entire distributed serverless applications, not just individual components. 2. Simplifies security management by automating verification of complex multi-module or microservice systems. 3. Increases confidence in application integrity and provenance, facilitating wider adoption of TEEs in cloud-native environments. 4. Reduces developer effort and expertise required to ensure end-to-end attestation and compliance. Target audience 1. Cloud service providers 2. Application framework developers (e.g., WasmCloud, Kubernetes) 3. Edge computing platform operators 4. Developers of confidential computing and attestation tools Business model Open source distribution model, enabling broad adoption and community-driven improvements. Designed for indirect exploitation by integration into orchestration platforms, cloud stacks, or confidential computing toolchains, rather than through direct monetisation. Exploitation channels 1. Public code repositories (e.g., GitHub, GitLab) to release and maintain software openly. 2. Collaboration with open-source communities to co-develop and improve projects. 3. Open licensing models (e.g., Apache 2.0, MIT, CC0) that encourage adoption and contribution. 4. Integration into wider open ecosystems (e.g., Linux Foundation projects, CNCF). 5. Promotion through academic publications, workshops, and conferences to increase visibility. 6. Participation in open innovation networks and consortium to align project goals with community needs. Risks & Challenges Market PositionDefine the place the product/service aims to occupy in the market, e.g., is it a premium offering, a budget solution, or a niche product? This solution targets a niche market focused on secure, reliable attestation and analysis for distributed Wasm-based applications. It aims to be a specialised, advanced tool primarily used by cloud providers, framework developers, and security experts who require strong guarantees in confidential and serverless computing environments. Deployment Barriers 1. Requires extensive integration across multiple components, such as adding new controlplane services and adapting service mesh configurations in Kubernetes environments. 2. Complexity in adapting existing infrastructure to support new verification and attestation mechanisms. 3. Potential compatibility challenges with diverse cloud-native platforms and orchestration tools. 4. Additional operational overhead during deployment due to necessary architectural changes and component coordination. Other Challenges 1. Limited long-term funding and resources for continuous development and support after project completion. 2. Difficulty in ensuring consistent updates and compatibility with evolving cloud-native ecosystems. 3. Dependence on external open-source communities for ongoing maintenance and feature enhancements. 4. Risk of fragmentation if multiple independent implementations arise without centralised coordination. Mitigation Measures 1. Integrate the solution into well-established open-source projects with active communities for long-term maintenance. 2. Establish partnerships with industry stakeholders to share responsibility for ongoing development and support. ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 118 - August 31, 2025 3. Provide thorough documentation and developer guides to encourage community contributions and adoption. 4. Design modular, extensible components to facilitate easy updates and integration by third parties. Other Solutions (Current State of the Art) 1. Confidential container platforms (e.g., Kata Containers, gVisor) offer attestation for individual application components within secure enclaves. 2. Service mesh frameworks (e.g., Istio, Linkerd) provide runtime security and policy enforcement but lack holistic attestation across distributed components. 3. Existing Wasm runtime tools provide have platform-specific notions of application identity, not allowing for cross-platform static analysis of multi-module interactions. 4. Traditional attestation methods focus on single-host scenarios and do not fully address distributed or serverless application environments. Table 22: Accelerated microservices interconnection - POLITO Name of Result Accelerated microservices interconnection Partner Name POLITO Type of Result Software Associated WP, Task & Demonstrator WP2/T2.3, Demonstrator 1 Brief Description - what it does This software component provides technologies and solutions to accelerate communication both within and between nodes (intra-node and inter-node) in a computing cluster. Leveraging advanced Linux capabilities such as eBPF as well as RDMA compatible hardware, the component aims to significantly increase network throughput and reduce latency for typical cluster workloads, thus enhancing performance of microservices communication. Background IP No Current/ Expected TRL Current: TRL2 / Expected: TRL4 Use of IP/Result Exploitation Use Research Services Can it be Protected? Yes IPR Protection Method Copyright Customers/ Users/Target Audience 1. The Linux open-source community 2. The Kubernetes open-source community 3. Small/medium scale cloud providers 4.Cloud infrastructure administrators seeking network performance improvements Pains of customers/Users 1. Insufficient network performance for cloud native applications 2. Low resource utilisation when running networking-heavy workloads 3. Inefficient network layer in cloud deployments Benefit of Customers/Users 1. Improved network throughput and latency 2. Faster performance for workloads relying on east-west traffic patterns 3. Better utilisation of RDMA hardware in data centers 4. Potential cost savings by enhanced networking efficiency and reduced CPU overhead Target audience 1. Cloud providers or cloud infrastructure admins looking for technology able to provide faster networking throughput and latency compared to established network CNI plugins/able to make use of available RDMA hardware for node-to-node traffic 2. Linux/network research community Business model POLITO is a public Technical University. For this reason, it is not pursuing direct commercial exploitation of its research products. Rather, POLITO's mission is to disseminate and transfer its knowledge and research products to other stakeholders interested in using or building products based on them. At the same time, POLITO aims to get funding for its activities by participating in funded research programs and collaborations with industrial partners and to improve its external visibility. POLITO's exploitation goals related to this component will be pursued mainly through the following activities: ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 119 - August 31, 2025 1. The open-source release of the software, to encourage adoption, collaboration, and further development by industry and research communities. 2. The promotion of collaborations with existing industrial stakeholders interested in using or exploiting the component, or of new spinoffs for the commercial exploitation of the component. 3. The capitalisation of the gained experience and its use in participating in forthcoming funded project proposals, dissemination, and technology transfer initiatives. Exploitation channels 1. Open-source software projects 2. Engagement with Linux and networking communities 3. Collaborations with industry partners 4. Participation in funded research initiatives Risks & Challenges Market PositionDefine the place the product/service aims to occupy in the market, e.g., is it a premium offering, a budget solution, or a niche product? This solution aims to occupy a niche as a high-performance, research-driven acceleration technology for microservices networking, targeting cloud-native infrastructure and advanced Kubernetes deployments that require cutting-edge networking performance. Deployment Barriers 1. Development of the inter-node traffic acceleration, specifically in achieving target 100% speedup via traffic rerouting through a TCP/RDMA proxy 2. Requires RDMA-capable NIC hardware 3. Requires installing custom kernel/kernel module for intra-node acceleration 4. Possible integration challenges with established Kubernetes network plugins and infrastructures Other Challenges 1. Maintaining compatibility with vast ranges of Linux kernel versions and RDMA network adapter vendor/technology 2. Properly supporting existing policy enforcement capabilities of modern cloud network infrastructures 3. Gaining broad community adoption given the strict software and hardware requirements Mitigation Measures 1. RDMA proxy performance could be improved by using alternative mechanisms for intercepting application traffic and forwarding it through the proxy, if achieved performance with the original method is considered insufficient 2. Provide sufficient developer and end-user documentation to ease the transition from other network infrastructures 3. Implement policy enforcement in the custom network data path 4. Engage early with the Linux and low-level networking communities Other Solutions (Current State of the Art) 1. Cilium Kubernetes CNI plugin: popular comprehensive container networking solution using eBPF technology to achieve faster performance than native Linux networking 2. Calico Kubernetes CNI plugin: alternative Kubernetes CNI implementation with several available network backends, including eBPF and VPP for userspace-driven networking 3. RDMA-aware Kubernetes CNI plugins: other existing projects/proof of concepts found in the open-source domain that implement RDMA-accelerated networking for Kubernetes clusters Table 23: eBPF distributed state synchronisation - POLITO Name of Result eBPF distributed state synchronisation Partner Name POLITO Type of Result Software Associated WP, Task & Demonstrator WP2/T2.3, Demonstrator 1 Brief Description - what it does This component develops techniques and algorithms for fast and efficient state sharing between distributed eBPF probes. Specifically, it extends the core eBPF concept of maps to allow sharing of data across server boundaries, much like current implementations offer inter-probe, inter-CPU and kernel-to-userspace (and vice-versa) data sharing. Internally, the component makes use of eBPF-powered instrumentation to intercept map updates and kick-off the synchronisation protocol, which is tuned for the lowest possible latency by ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 120 - August 31, 2025 making use of AF_XDP network sockets and fast XDP map synchronisation to achieve sub-100us end-to-end delays. Background IP None Current/ Expected TRL Current: TRL1 / Expected: TRL4 Use of IP/Result Exploitation Use Research Services Can it be Protected? Yes IPR Protection Method Copyright Customers/ Users/Target Audience 1. The Linux open-source community 2. Researchers interested in distributed data structures 3. eBPF developers looking for ways to extend the reach of maps to networked servers 4. Academia and industry researchers working in the field of low latency and eBPF technologies Pains of customers/Users 1. Need to distribute eBPF state across networked hosts 2. System inefficiency due to having to rely on distributed data structures for eBPF programs based on user-space implementations 3. Required time commitment of implementing custom distributed data structures 4. Excessive latency of existing synchronisation solutions Benefit of Customers/Users 1. Ability to access data structures that are internally distributed across a network 2. Better performance compared to competition (sub 100us target for convergence time) 3. Reduced complexity and developer effort by relying on ready, high-performance solution 4. Enabling new use-cases for deploying eBPF to multi-server infrastructure, like Kubernetes clusters Target audience 1. Linux open-source community 2. eBPF developers 3. Researchers in distributed systems 4. Researchers in low-latency communication 5. Academia and industry experts in advanced networking solutions Business model POLITO is a public Technical University. For this reason, it is not pursuing direct commercial exploitation of its research products. Rather, POLITO's mission is to disseminate and transfer its knowledge and research products to other stakeholders interested in using or building products based on them. At the same time, POLITO aims to get funding for its activities by participating in funded research programs and collaborations with industrial partners and to improve its external visibility. POLITO's exploitation goals related to this component will be pursued mainly through the following activities: 1. The open-source release of the software, to encourage adoption, collaboration, and further development by industry and research communities. 2. The promotion of collaborations with existing industrial stakeholders interested in using or exploiting the component, or of new spinoffs for the commercial exploitation of the component. 3. The capitalisation of the gained experience and its use in participating in forthcoming funded project proposals, dissemination, and technology transfer initiatives. Exploitation channels 1. Open-source software repositories and projects 2. Engagement with Linux and eBPF communities 3. Collaborations with industry partners 4. Participation in funded research initiatives Risks & Challenges Market PositionDefine the place the product/service aims to occupy in the market, e.g., is it a premium offering, a budget solution, or a niche product? This product targets a niche market focused on advanced, low-latency distributed state synchronisation for eBPF-based systems. It aims to be a cutting-edge, research-driven solution appealing primarily to developers, researchers, and organisations requiring highperformance, scalable networking and monitoring capabilities in cloud-native and data center environments. Deployment Barriers 1. Meeting the stringent target end-to-end latency of 100us 2. Developing and integrating the solution with the Linux kernel via custom kernel ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 121 - August 31, 2025 modules or eBPF libraries 3. Ensuring compatibility across kernel versions 4. Ensuring satisfactory performance across different hardware and software configurations Other Challenges 1. Managing complexity of distributed consensus and leader election algorithms while retaining low-level access to network adapter queues via AF_XDP sockets for minimum latency Mitigation Measures 1. Engage with the community to gather feedback and push for adoption 2. Explore the use of high-level sockets (UDP or TCP) to simplify development without sacrificing latency Other Solutions (Current State of the Art) 1. Current eBPF implementation offers several map types, none of which are distributed across a network 2. Other user-space libraries and databases implement distributed data structures, though they are inaccessible by eBPF programs 3. Experimental projects in distributed kernel data structures, but lacking widespread adoption or performance guarantees Table 24: NETTO - A tool to measure the cost of the Linux network stack in real-time - POLITO Name of Result NETTO - A tool to measure the cost of the Linux network stack in real-time Partner Name POLITO Type of Result Software Associated WP, Task & Demonstrator WP2/T2.3, Demonstrator 1 Brief Description - what it does NETTO is a lightweight Linux utility that measures the CPU overhead of network functions (e.g., bridging, routing, filtering) in real time. Built on eBPF and perf events, it uses a custom sampling-based profiler to extract stack traces and compute usage metrics with minimal overhead. Its extensible design supports continuous monitoring and seamless adaptation to new protocols and workloads, making it ideal for identifying performance bottlenecks and guiding optimisation of the Linux networking stack. Background IP None Current/ Expected TRL Current: TRL3 / Expected: TRL4 Use of IP/Result Exploitation Use Research Services Can it be Protected? Yes IPR Protection Method Copyright Customers/ Users/Target Audience 1. System administrators wanting to inspect their Linux servers' network performance and bottlenecks 2. Linux networking researchers and performance engineers 3. Developers in the Linux and eBPF open-source community 4. Infrastructure and DevOps professionals managing high-throughput systems Pains of customers/Users 1. Limited visibility of the Linux network stack and its performance due to opaque and coarse grained procfs metrics 2. Difficulty in automating infrastructure actions based on instantaneous network stack CPU usage (e.g., scaling or consolidation) 3. High overhead and complexity of existing tools for deep network stack performance inspection 4. Inability to pinpoint specific kernel functions causing high network-related CPU overhead in production systems Benefit of Customers/Users 1. Real-time, low overhead visibility of the amount of CPU consumed by the Linux Kernel Network Stack 2. Ability to evaluate potential advantages of adopting hardware network accelerators such as SmartNICs for network efficiency and overhead 3. Opportunity to learn about the deep technical aspects contributing to high observed Linux network stack CPU utilisation ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 128 - August 31, 2025 Current/ Expected TRL Current: TRL1 / Expected: TRL3 Use of IP/Result Exploitation Use Further R&D Projects Can it be Protected? No IPR Protection Method N/A Customers/ Users/Target Audience 1. Internal development teams within ERF and related business units aiming to enhance product observability features for serverless Wasm components in Kubernetes environments or to use the observability data for AI-driven automation. 2. Direct customers of ERF: communication service providers interested in improving monitoring of serverless WASM workloads and using the information for AI-driven automation. 3. Indirect customers of ERF (customers of customers): Developers and integrators of AIdriven intrusion detection and cybersecurity systems. Pains of customers/Users 1. Lack of efficient and scalable observability tools tailored for WASM-based serverless workloads, especially in edge and IoT contexts. 2. Difficulty in tracing faults and performance bottlenecks in highly dynamic, ephemeral serverless environments. 3. High resource overhead and cost associated with naive or continuous monitoring approaches. 4. Limited tooling support for integrating observability with AI-based security and orchestration systems. Benefit of Customers/Users 1. Enables targeted, on-demand observability with minimal performance and resource overhead. 2. Improves fault diagnosis and performance tuning in serverless WASM applications. 3. Supports integration with AI intrusion detection systems for proactive security monitoring. 4. Facilitates adoption of serverless WASM by providing essential operational visibility. Target audience 1. Telecom operators and cloud service providers exploring WASM serverless workloads. 2. IoT platform providers deploying edge workloads with WASM runtimes. 3. Security solution developers integrating observability with intrusion detection. 4. Kubernetes and cloud-native ecosystem developers focusing on WASM runtimes. Business model 1. Business Model Mainly internal use and integration within ERF’s product offerings and services. 2. Potential future commercialisation through consulting, support, and integration services tailored for telecom and cloud customers adopting WASM serverless. 3. Collaboration with ecosystem partners for joint innovation and incorporation into broader monitoring platforms. Exploitation channels 1. Internal technology transfer and incorporation into ERF’s product roadmap. 2. Dissemination through research publications, workshops, and EU project collaborations. 3. Engagement with open-source communities related to WASM runtimes and Kubernetes observability tools. 4. Participation in standardisation and industry working groups for observability and serverless technologies. Risks & Challenges Market PositionDefine the place the product/service aims to occupy in the market, e.g., is it a premium offering, a budget solution, or a niche product? A niche but strategically important observability solution focused on emerging WASM serverless workloads in edge and cloud environments, aiming to complement existing monitoring platforms with WASM-specific capabilities. Deployment Barriers 1. Wasm serverless adoption in Telco and cloud domains is still in early stages; market traction is uncertain. 2. Rust language has the most mature support for Wasm but other languages are still used widely in the industry and the support for other languages needs to evolve 3. A limitation in the current prototype is that it requires slight modification of existing workloads for exact identification serverless functions; coarse-grained identification is possible without any modifications. 4. Even though smart and dynamic rule based triggering can reduce the overhead of the ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 129 - August 31, 2025 observability framework, eBPF uprobe incurs always some overhead due to userspacekernelspace switching. This is independent of whether TLS is used or not. Also, we had enable debug symbols in the run-time for Spinkube which has a slight impact on its performance. Other Challenges 1. Observing Rust based function and data structures is challenging with eBPF uprobe. Hence, instead of observing the application, we are observing the run-time. 2. Keeping the framework lightweight enough for resource-constrained edge deployments. 3. Coordinating standardisation efforts around WASM observability interfaces and eBPF usage. 4. Maintaining compatibility with evolving WASM runtimes and Kubernetes distributions. 5. Balancing security and privacy concerns when monitoring network traffic and application behavior. Mitigation Measures 1. Actively promote the technology within ERF and partner networks to encourage early adoption and feedback. 2. Collaborate closely with WASM runtime and Kubernetes communities to align development and integration efforts. 3. Engage with security and standards bodies to build trust and gain acceptance. 4. Parsing of HTTP headers was difficult in the kernelspace eBPF code in kernel so it was handled in the userspace code. Developing support for kernelspace parsing would require a lot of effort but could potentially improve the performance of the prototype but this remains to proven. 5. Based on the experience gathered during the project, we believe that the userspacekernelspace context switching performance overhead in eBPF uprobe could be mitigated to some extent by implementing the observability framework without eBPF, entirely in the userspace. For example, Frida.js library is a good example of this but does not have any support for Wasm. This could be achieved by two different approaches: Ideally, a language-agnostic solution for Wasm bytecode operating in the run-time, or, alternatively, a language-specific solution(s) that is incorporated into the application before it Is compiled into Wasm-bytecode (caveat: requires modification of workloads). However, both a and b require work beyond the grant agreement of the project. Other Solutions (Current State of the Art) 1. Basic OpenTelemetry instrumentation for serverless workloads (lacks WASM-specific features). 2. SpinKube has built-in instrumentation but it provides only static information. Manual instrumentation also possible but requires modification of all workloads. 3. Proprietary user-space observability tools (e.g., delis/observe-sdk) with limited transparency and availability. 4. Kernel-space eBPF monitoring solutions targeting generic workloads but without WASM-specific serverless support and without the ability to inspect TLS workloads. 5. Emerging WASM runtime observability projects like Wasm-bpf integrated with WasmEdge (still limited in feature scope). 6. Frida.js supports observability of userspace applications without the kernelspaceuserspace overhead of eBPF uprobe but lacks Wasm (and Rust) support. 7. wasm-bpf is Wasm eBPF library, toolchain and runtime, that is used also by WasmEdge serverless platform. We are utilising the library in our protototype Table 29: Remote Attestations platform - THD Name of Result Remote Attestations platform Partner Name THD Type of Result Software, interface definitions Associated WP, Task & Demonstrator WP3/T3.3, Demonstrator 2 Brief Description - what it does A remote attestation platform will support multiple CSPs (Google GCP, Microsoft Azure) and TEE architectures (ex. Intel TDX, AMD SEV). Main abstraction work for TEEs to be done at the Attester side producing wrapped evidence in the attester, unwrapped at the verifier. Verifier calls based on original evidence respective trust authority for attestation. Background IP Yes Current/ Expected TRL Current: TRL2 / Expected: TRL4 ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 130 - August 31, 2025 Use of IP/Result Exploitation Use Further R&D Projects Can it be Protected? Potentially IPR Protection Method Patent Customers/ Users/Target Audience 1. Confidential Computing solution providers 2. Security service providers 3. Developers of application using ELASTIC framework Pains of customers/Users 1. Evidence and claim used in Remote Attestation (RA) is HW TEE dependent. 2. Evidence and claim used in RA is SW OS dependent. 3. RATS is standardised as a procedure but not in detail concerning evidence, and hence each TEE/SW stack has its nuances. 4. This also forms a barrier for new market entrance of HW based CC solution providers. Benefit of Customers/Users 1. The objective is to make RA more hardware-agnostic and new TEEs easier to be implemented and considered for RA. 2. Enable easier market entry and wider adoption of new Confidential Computing solutions by reducing integration complexity. 3. Improve interoperability across diverse hardware and software environments, enhancing system flexibility. 4. Supports scalable deployment in multi-cloud and multi-tenant scenarios, increasing security assurance. Target audience Confidential Computing developers of using the ELASTIC framework. Business model The solution is envisaged to be incorporated/included into future Thales products. Exploitation channels 1. Collaboration with cybersecurity requirements across public clouds implementations and research projects, leveraging Thales’s industry expertise to drive innovation and validate the component. 2. Development of joint demonstrators and architectures with key partners, focusing on security-critical cloud and edge computing environments. 3. Integration of the remote attestation platform into Thales’s cybersecurity cloud and edge computing product lines, targeting sectors such as finance, IT providers, defense, telecom, and critical infrastructure. 4. Active participation in further R&D projects to continuously extend and enhance the platform’s capabilities and market readiness. Risks & Challenges Market PositionDefine the place the product/service aims to occupy in the market, e.g., is it a premium offering, a budget solution, or a niche product? The remote attestation platform aims to occupy a premium, high-security niche in the market, targeting organisations requiring robust, hardware-agnostic attestation solutions for confidential computing in public clouds. It differentiates itself through interoperability, scalability across multi-cloud and distributed environments, and suitability for security-critical sectors like finance, IT service providers, defense and telecom. Deployment Barriers Each of the attestation platforms and their flow and formats has its nuances, but the core principles of measurement, signed report generation, and cryptographic verification are common. Deployment barriers include: 1. Diverse attestation platforms have unique flows and evidence formats; the solution must be generic to support current and future standards. 2. Limited standardisation across confidential computing technologies slows widespread adoption. 3. Hardware dependencies and vendor-specific implementations complicate interoperability in multi-cloud environments. 4. Migration of workloads protected by hardware-bound enclaves presents technical and operational challenges. Other Challenges Technical challenges are under assessment to ensure robustness and scalability, including: 1. Integration and adaptation with the overall ELASTIC Hardware Abstraction Layer (HAL) architecture require careful alignment. 2. Ensuring low-latency and efficient performance in diverse deployment scenarios to meet operational security requirements. 3. Managing evolving security threats and maintaining up-to-date protections in a rapidly changing environment. ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 131 - August 31, 2025 Mitigation Measures 1. Early collaboration with HAL developers to incorporate necessary enhancements, especially for the Verifier component. 2. Implementation robustness, continuous testing and validation to meet stringent security requirements, ensure compatibility across diverse hardware and software platforms. 3. Adoption of modular design principles to allow flexible integration and futureproofing. 4. Active participation in standards evolution to quickly adapt protocols and interfaces. Other Solutions (Current State of the Art) 1. Hardware-specific attestation solutions tailored to each existing TEEs, limiting interoperability and hindering new entrants. 2. Proprietary platforms offered by major cloud providers with limited cross-vendor compatibility. 3. Emerging standardised frameworks (e.g., RATS) still lacking full detail and adoption across diverse TEEs. 4. Lightweight attestation protocols focusing on specific use cases but not yet widely generalised. Table 30: Key Broker Service - THD Name of Result Key Broker Service Partner Name THD Type of Result Software, interface definitions Associated WP, Task & Demonstrator WP3/T3.3, Demonstrator 2 Brief Description - what it does The key broker service provides keys after an attestation service for sealing secrets inside the TEE. The key broker service may be a cloud service or a local service as in Demo 2, utilization of the Key Broker Service will be used to control securely moving "workloads" from on-prem infrastructures to public cloud environments by releasing key after successful attestation to enable the secure migration to proceed. Background IP Yes Current/ Expected TRL Current: TRL2 / Expected: TRL4 Use of IP/Result Exploitation Use Further R&D Projects Can it be Protected? Potentially IPR Protection Method Patent Customers/ Users/Target Audience 1. CC and Cloud Service Providers (CSPs): Seeking to enhance trust and security in multi-tenant, multi-cloud environments by offering hardware-agnostic key management linked to attestation. 2. Enterprises and Organisations: Handling sensitive workloads requiring strict key control, confidentiality, and compliance in public clouds, especially in regulated industries like IT service providers, defence, finance, and healthcare. 3. Security Vendors and System Integrators: Developing or integrating confidential computing and secure cloud solutions, needing flexible key provisioning tied to attestation results. 4. Developers of Confidential Computing Applications: Requiring reliable key management and attestation mechanisms to protect workloads running in TEEs. ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 132 - August 31, 2025 Pains of customers/Users 1. Concerns on data protection when moving sensitive "Workloads" to public clouds. 2. Cloud Service Providers (CSPs): Seeking to enhance trust and security in multitenant, multi-cloud environments by offering hardware-agnostic key management linked to attestation. 3. Enterprises and Organisations: Handling sensitive workloads in the Public Clouds requiring strict key control, confidentiality, and compliance, especially in regulated industries like finance, IT service providers, defence and healthcare. 4. Security Vendors and System Integrators: Developing or integrating confidential computing and secure cloud solutions, needing flexible key provisioning tied to attestation results. 5. Developers of Confidential Computing Applications: Requiring reliable key management and attestation mechanisms to protect workloads running in TEEs. Benefit of Customers/Users 1. Improved security for workload migration and secure storage in public clouds. 2. Enhanced end-to-end security with encrypted software images and secure key provisioning only after attestation success by offering customers full control over cryptographic keys through BYOK/HYOK models and reducing dependency on cloud providers. 3. Improved trust and compliance in cloud environments, particularly for sensitive or regulated applications. 4. Flexibility to integrate with various confidential computing technologies and cloud platforms. Target audience Developers and providers of Confidential Computing based solutions Business model Solution is to be included in conjunction with Remote Attestation Service, Confidential Computing and secure data storage. Exploitation channels 1. Integration into Thales cybersecurity and cloud product lines, especially targeting finance, IT service provides, defence, telecom, and regulated industries. 2. Collaborative projects and demonstrators with industry and research partners focusing on secure cloud and edge computing. 3. Engagement with standards bodies and open-source communities to promote interoperability and adoption. 4. Further R&D projects to enhance functionality and adapt to emerging confidential computing platforms. Risks & Challenges Market PositionDefine the place the product/service aims to occupy in the market, e.g., is it a premium offering, a budget solution, or a niche product? The key broker services aim to address high-security markets targeting organizations requiring robust, hardware-agnostic attestation solutions for confidential computing in public clouds. It differentiates itself through interoperability, scalability across on-prem, multi-cloud and distributed environments applications and suitability for security-critical sectors like finance, IT service providers, defense and telecom. Deployment Barriers 1. API to key broker service interoperability interfacing with Verifier (i.e. interfacing via HAL etc.) 2. Complexity of integrating with diverse TEEs and cloud environments. 3. Need for widespread standardisation and interoperability in key provisioning and attestation protocols. 4. Customer adoption challenges due to legacy key management practices. 5. Regulatory and compliance considerations in different markets. Other Challenges 1. Ensuring low latency and scalability in key provisioning workflows. 2. Aligning with the evolving Elastic Hardware Abstraction Layer architecture. 3. Maintaining compatibility with heterogeneous confidential computing ecosystems. Mitigation Measures 1. Early collaboration with HAL development to ensure robust integration. 2. Active participation in standardisation efforts to drive common protocols. 3. Robust modular design to ease adaptation to different deployment scenarios. Other Solutions (Current State of the Art) 1. Cloud provider-managed key vaults tightly coupled with their platforms, limiting portability and customer control. 2. Vendor-specific key provisioning tied to particular TEEs without general abstraction layers. 3. Manual or semi-automated key management workflows lacking integration with attestation processes. 4. Emerging standards like IETF RATS framework not yet widely implemented for key provisioning tied to attestation outcomes. ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 133 - August 31, 2025 Table 31: Multi-platform attestation component - ERF Name of Result Multi-platform attestation component Partner Name ERF Type of Result Software, interface definitions Associated WP, Task & Demonstrator WP3/T3.3, Demonstrator 1 Brief Description - what it does The component enables verification of attestation evidence from multiple platforms via a unified interface based on the WebAssembly component model. It provides tools for entities to verify trust across different TEEs and supports attestation of data producers and consumers, e.g., within ELASTIC’s Data Fabric. Background IP "Multi-Platform Attestation Verification" MSc thesis Current/ Expected TRL Current: TRL2 / Expected: TRL3 Use of IP/Result Exploitation Use Further R&D Projects Can it be Protected? No IPR Protection Method N/A Customers/ Users/Target Audience 1. Developers and providers of Confidential Computing based solutions 2. Communication service providers that use Confidential Computing based solutions 3. System integrators and cloud providers requiring standardised attestation verification. 4. Security and compliance teams seeking unified attestation tools across heterogeneous hardware. Pains of customers/Users 1. Current solutions for remote attestation are hardwareand cloud-vendor specific 2. Lack of standards, and adoption of standards, for remote attestation 3. Stricter security requirements overall motivate protection of data in use, but the lack of unified attestation mechanisms slows down the adoption of Confidential Computing 4. Attestation typically relies on centralised remote services Benefit of Customers/Users 1. Provides a vendor-agnostic, unified approach to remote attestation, reducing dependency on proprietary solutions. 2. Accelerates deployment of Confidential Computing by enabling attestation through a common mechanism even before full industry-wide standardisation. 3. Simplifies integration of attestation verification into orchestration and application layers via standardised APIs and portable Wasm components. 4. Supports trust establishment across heterogeneous platforms, enhancing security and compliance. Target audience 1. Developers and providers of Confidential Computing solutions 2. Cloud, edge, and communication infrastructure providers integrating secure attestation mechanisms 3. Vendors of orchestration frameworks needing platform-agnostic attestation support 4. Security architects implementing trust and compliance in multi-platform environments Business model The component is not intended as a standalone product but to be integrated into larger products or services leveraging Confidential Computing or attestation, such as ELASTIC’s Data Fabric. Monetisation is expected via inclusion in commercial offerings, support contracts, or enhanced security services. Exploitation channels 1. Integration within ELASTIC project deliverables and ecosystem. 2. Incorporation into demonstrator and commercial Confidential Computing solutions. 3. Potential collaboration with standardisation bodies and industry consortia to align with evolving attestation protocols. Risks & Challenges Market PositionDefine the place the product/service aims to occupy in the market, e.g., is it a premium offering, a budget solution, or a niche product? This is a niche component aimed at advanced security use cases in Confidential Computing. It is not a standalone product but intended to be integrated into premium platforms that require secure, cross-platform attestation. It fills a gap where flexible, standards-based attestation support is still missing. ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 134 - August 31, 2025 Deployment Barriers 1. Confidential Computing adoption is currently limited by hardware availability and ecosystem maturity, including standardisation overall. 2. Integration effort required to support multiple TEE platforms and maintain Wasm components. 3. Performance overhead associated with attestation verification and using TEEs in runtime environments. 4. Possibly a reduced need of this solutions if standards get more widely adopted. Other Challenges 1. Keeping pace with evolving standards (e.g., IETF RATS, EAT) and ensuring compatibility. 2. Ensuring trust in dynamically obtained verification modules (e.g., Wasm-based components). 3. Balancing security with performance in constrained or edge environments. 4. Coordinating integration efforts across diverse platforms and partners in multi-vendor environments. Mitigation Measures 1. Modular design allows incremental support of new TEEs and standards. 2. Optimisation efforts to minimise performance impact of attestation verification. 3. Promotion of open collaboration to drive ecosystem adoption. 4. Monitoring of, and potential engagement with, hardware vendor solutions and standards bodies to stay aligned with emerging protocols Other Solutions (Current State of the Art) 1. Commercial attestation services (e.g., Intel TA, Microsoft MAA) 2. Open source verification frameworks (e.g., VERAISON, Trustee) 3. Emerging standard formats and protocols for attestation (e.g., IETF EAT) Table 32: Light-weight Attribute-based Access Control (ABAC) solution - THS Name of Result Lightweight Attribute-based Access Control (ABAC) solution Partner Name THS Type of Result Software Associated WP, Task & Demonstrator WP2/T2.4, Demonstrator 1 Brief Description - what it does This component aims to enforce attribute-based access control (ABAC) policies on WASM orchestration, and also on interactions between WASM containers and their environment. It mainly consists of user plane components playing the role of PEPs (Policy Enforcement Point) which may interact with control plane components for authentication, authorisation and auditing policy enforcement. This is also an approach to apply the NIST Zero Trust Architecture (NIST SP 1800-35) to WASM container environments. Background IP - AuthzForce Enterprise software project (ABAC framework). Note that there is also a Community Edition that is free open source. - Patent WO2020127400A1 - European FP7 project "FI-CORE" (FIWARE) Current/ Expected TRL Current: TRL3 / Expected: TRL4 Use of IP/Result Exploitation Use Further R&D Projects Can it be Protected? Potentially IPR Protection Method Patent Customers/ Users/Target Audience 1. Security-critical edge computing infrastructure providers 2. Soverign cybersecurity service providers (especially for RISC-V platforms) 3. Developers of lightweight container orchestration platforms for constrained environments 4. Public sector entities and national security agencies requiring fine-grained, embedded access control solutions Pains of customers/Users 1. Insufficient security measures for edge and containerised environments 2. Resource constraints (CPU, memory, storage) limiting the use of advanced ABAC solutions 3. Inability to enforce fine-grained access control on emerging Edge platforms like RISCV ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 135 - August 31, 2025 4. Challenges maintaining security during control plane outages, network disruptions, limited bandwidth. Benefit of Customers/Users 1. Enhanced fine-grained and adaptable access control tailored to diverse security needs 2. Ability to enforce multiple security levels simultaneously on a single edge device 3. Improved resilience through decentralised and offline access control enforcement 4. Compatibility with emerging Edge platforms like RISC-V, enabling future-proof deployments Target audience 1. Edge infrastructure operators deploying security-critical services 2. Vendors integrating ABAC solutions into container orchestration platforms 3. System integrators delivering secure edge computing solutions for industrial and telecom sectors 4. Cybersecurity teams managing access control in resource-constrained environments, especially on RISC-V devices Business model Not offered standalone but integrated in a container orchestration offer, or to a larger extent, in a secured edge computing solution (e.g., ELASTIC IoT Data Fabric). Exploitation channels 1. Collaboration with cybersecurity and telecom research projects, leveraging Thales’s industry expertise. 2. Joint demonstrators and pilot deployments with key partners in security-critical edge environments. 3. Integration into Thales’s cybersecurity and edge computing solutions for sectors like defense and telecom. 4. Engagement in further R&D projects to extend and enhance the solution. Risks & Challenges Market PositionDefine the place the product/service aims to occupy in the market, e.g., is it a premium offering, a budget solution, or a niche product? The Lightweight ABAC solution targets a niche, premium market focused on secure, resource-constrained edge environments like industrial automation and telecom. It offers advanced, fine-grained access control for specialised use cases rather than mass-market deployment. Deployment Barriers 1. Porting component software to fairly young RISC-V ecosystem (immature in some security aspects and not yet massively adopted) 2. Lacking necessary WASM APIs and extensibility points to integrate the solution 3. Resource constraints on edge devices require highly optimised, lightweight solutions. 4. Evolving and fragmented WASM security standards may slow adoption and interoperability. Other Challenges 1. Difficulties to acquire the necessary infrastructure / hardware for testing 2. Rapidly evolving edge computing environments complicate long-term solution stability. 3. Ensuring compatibility across heterogeneous platforms and devices. 4. Balancing security with performance on resource-constrained systems. Mitigation Measures 1. Active participation in RISC-V standardisation and ecosystem growth. 2. Engagement in WASM standards development and community collaboration. 3. Continuous adaptation to emerging platform requirements. 4. Building partnerships to access diverse testing environments. Other Solutions (Current State of the Art) 1. Traditional ABAC systems mostly target cloud or more powerful edge environments but don’t fit well on constrained devices. 2. Current WASM orchestration platforms rarely integrate comprehensive ABAC enforcement tailored to container interactions and lifecycle. Table 33: WASI flexibly-defined capabilities - AAL Name of Result WASI flexibly-defined capabilities Partner Name AAL Type of Result Software Associated WP, Task & Demonstrator WP1/T1.2, Demonstrator 2 ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 136 - August 31, 2025 Brief Description - what it does This component enhances WASI interfaces by enabling flexible, domain-specific access control policies beyond standard capability-based restrictions. It ensures that precise security rules—such as file write permissions with format compliance—can be enforced without the need for specific runtime support.. Background IP No Current/ Expected TRL Current: TRL1 / Expected: TRL3 Use of IP/Result Exploitation Use Direct Licensing to Customer Can it be Protected? Yes IPR Protection Method Copyright Customers/ Users/Target Audience 1. Users of Wasm-based cloud computing tools such as WAC and WasmCloud 2. WebAssembly application developers needing customisable access control 3. Cloud service providers deploying secure, modular Wasm applications 4. Security architects implementing fine-grained policy enforcement in Wasm environments Pains of customers/Users 1. Combining mutually distrusting WebAssembly applications requires specific support by applications 2. Existing WASI capabilities are runtime-specific and cannot enforce complex or domainspecific policies 3. Difficulty ensuring security policies without hindering application development or performance 4. Lack of tools for dynamic, fine-grained access control tailored to diverse use cases Benefit of Customers/Users 1. System operators can define custom access control policies when composing WebAssembly applications 2. Improved security by enforcing domain-specific and fine-grained restrictions on resources 3. Enhanced flexibility to adapt policies without limiting application development 4. Better assurance for attestation relying parties that dataflows and resources are properly protected Target audience 1. WebAssembly-based application developers 2. Cloud service providers using Wasm workloads 3. Developers of secure serverless and microservices platforms 4. Vendors and maintainers of Wasm runtime environments and tools Business model Open source distribution model, enabling broad adoption and community-driven improvements. Designed for indirect exploitation by integration into orchestration platforms, cloud stacks, or confidential computing toolchains, rather than through direct monetisation. Exploitation channels 1. Public code repositories (e.g., GitHub, GitLab) to release and maintain software openly. 2. Collaboration with open-source communities to co-develop and improve projects. 3. Open licensing models (e.g., Apache 2.0, MIT, CC0) that encourage adoption and contribution. 4. Integration into wider open ecosystems (e.g., Linux Foundation projects, CNCF). 5. Promotion through academic publications, workshops, and conferences to increase visibility. 6. Industry partnerships that adopt and support the open-source software as part of their offerings. 7. Participation in open innovation networks and consortiums to align project goals with community needs. Risks & Challenges Market PositionDefine the place the product/service aims to occupy in the market, e.g., is it a premium offering, a budget solution, or a niche product? A niche open-source solution enabling flexible, fine-grained access control for WebAssembly applications, aimed at developers and operators needing enhanced security and customisation. Deployment Barriers 1. Requires community agreement to integrate new access control specifications into existing WASI standards. ELASTIC D6.2 HORIZON-JU-SNS-2023/№ 101139067 ELASTIC - 137 - August 31, 2025 2. Potential complexity in adapting existing tools and workflows to support flexible policies. 3. Possible resistance from developers due to increased configuration and learning curve. 4. Limited initial adoption without strong ecosystem support or demonstrable benefits. Other Challenges 1. Insufficient long-term resources for continuous development and support. 2. Difficulty securing ongoing funding for maintenance post-project. 3. Risk of project stagnation due to limited dedicated maintenance personnel. 4. Challenges in sustaining community engagement and contributions over time. Mitigation Measures 1. Integration of results into established open-source projects to ensure continued use and maintenance. 2. Embedding the solution within popular open-source tools to leverage community support. 3. Contributing code to active open-source ecosystems to reduce dependency on academic upkeep. 4. Collaborating with open-source communities to foster sustainable maintenance beyond the project lifecycle Other Solutions (Current State of the Art) 1. wasi-virt — a tool enabling WebAssembly modules to interpose on system interfaces for access control. 2. WebAssembly System Interface (WASI) — standard capabilities for sandboxed access control, though with limited flexibility. 3. Linux seccomp with BPF filters — kernel-level filtering for system calls, but less flexible and user-space accessible than Wasm solutions.