NSF SAFE-OSE: TianoShield - Improving the Security Posture of the TianoCore Ecosystem

NSF Award Search · 01002526DB NSF RESEARCH & RELATED ACTIVIT · $1,233,063 · view on nsf.gov ↗

Abstract

A firmware program is embedded in storage on a computer's motherboard to controls how computing devices start up their boot processes and interact with their operating systems after they are powered on. The program controls devices ranging from cloud servers to Internet of Things (IoT) platforms. The Unified Extensible Firmware Interface (UEFI) is an open standard for computing system firmware architecture. The TianoCore community implements various components of the UEFI. This implementation has resulted in a vibrant and mature open-source ecosystem with a significant impact on U.S. national security, safety, and privacy. Given the widespread use of the TianoCore repositories, security vulnerabilities could be leveraged by U.S. adversaries and other malicious actors to cause potentially massive-scale harm to U.S. citizens, businesses, and industries. This project focuses on enhancing the security of the TianoShield ecosystem and improving its overall open-source development process and practices. The enhancements and the tools developed as part of the TianoShield project can be extended to other ecosystems and repositories. Outcomes will include publication of experience reports, which can serve as references for future security enhancements. The TianoShield will advance knowledge in the fields of software security and software and systems engineering by mitigating the identified vulnerabilities in the source code of the TianoCore repositories and the UEFI supply chain

Key facts

NSF award ID
2534021
Awardee
University of Colorado at Colorado Springs (CO)
SAM.gov UEI
RH87YDXC1AY5
PI
Armin Moin
Primary program
01002526DB NSF RESEARCH & RELATED ACTIVIT
All programs
—
Estimated total
$1,233,063
Funds obligated
$1,233,063
Transaction type
Cooperative Agreement
Period
10/01/2025 → 09/30/2027