<?xml version="1.0" encoding="UTF-8"?><ns2:project xmlns:ns1="http://gtr.rcuk.ac.uk/gtr/api" xmlns:ns2="http://gtr.rcuk.ac.uk/gtr/api/project" xmlns:ns3="http://gtr.rcuk.ac.uk/gtr/api/fund" xmlns:ns4="http://gtr.rcuk.ac.uk/gtr/api/person" xmlns:ns5="http://gtr.rcuk.ac.uk/gtr/api/project/outcome" xmlns:ns6="http://gtr.rcuk.ac.uk/gtr/api/organisation" ns1:created="2026-07-08T08:44:08Z" ns1:href="http://gtr.ukri.org/gtr/api/projects/CAD23A42-9262-4254-B46B-FE920D176659" ns1:id="CAD23A42-9262-4254-B46B-FE920D176659"><ns1:links><ns1:link ns1:href="http://gtr.ukri.org/gtr/api/persons/46F58570-FE22-4F1D-9921-7050467E4616" ns1:rel="PM_PER"/><ns1:link ns1:href="http://gtr.ukri.org/gtr/api/organisations/9DC5AE7F-3EF1-4789-B619-EC8726A9D0A6" ns1:rel="LEAD_ORG"/><ns1:link ns1:href="http://gtr.ukri.org/gtr/api/organisations/9DC5AE7F-3EF1-4789-B619-EC8726A9D0A6" ns1:rel="PARTICIPANT_ORG"/><ns1:link ns1:end="2026-08-30T23:00:00Z" ns1:href="http://gtr.ukri.org/gtr/api/funds/3473C4C8-D63E-4412-9F35-6AAE59BEC510" ns1:rel="FUND" ns1:start="2025-03-01T00:00:00Z"/></ns1:links><ns2:identifiers><ns2:identifier ns2:type="RCUK">10134102</ns2:identifier></ns2:identifiers><ns2:title>Securing Multi-domain Intelligence, Surveillance &amp;amp; Reconnaissance With Next-Generation CHERI Systems Isolation &amp;amp; Enforcement</ns2:title><ns2:status>Active</ns2:status><ns2:grantCategory>Collaborative R&amp;D</ns2:grantCategory><ns2:leadFunder>Innovate UK</ns2:leadFunder><ns2:abstractText>Security is by far the biggest challenge facing computing today, with billions of dollars each year spent attempting to manage critical infrastructure, industrial and medical systems, and supply chains, against cyber warfare and malicious actors. Specifically, we continue to see failures in &amp;quot;end-to-end security up to the point of use&amp;quot;, creating major challenges where traditionally we rely on firewalled systems to create a safe domain in which to operate. We constantly encounter complex systems where the size of computer code is too big to protect or certify correctly, and constantly see compromises of critical data, control and hardware systems failing.

Utilising CHERI (Capability Hardware Enhanced RISC Instructions) next generation compute architectures, this project will leverage the innovative programmers' models to implement enhanced isolation, integrity, and availability, with a focus on three specific domains:

Firstly, the project will robustly secure communication across &amp;quot;end-to-end security to the point of use&amp;quot; through the implementation of updated network stacks utilizing a set of specifically crafted compartments. The work here covers the reimagining, development, and implementation of a modern network stack with the highest possible level of integrity. Following this significant testing and analysis is required to prove integrity and ensure no hidden vulnerabilities lurk in the implementation, a far more truculent challenge.

Secondly, we will look to implement a sensor-fusion application on the system, to provide an equivalent platform to those identified by the defense contractors we have engaged with. Initially focused on high-precisions data acquisition systems we will implement a multi-compartmentalized implementation that protects the raw data and enables scaling and data analysis within separate domains, ensuring transforms on the data are carefully managed and isolated from the application space.

Finally, we will look to extend this with a CHERI based actuator control system, providing full isolation of system control components, but with integration into the secure communication stack. This will enable us to benchmark and evaluation the performance overhead of CHERI and refine overall system performance prior to the systems being consumed into end applications.

Ultimately this project will support dramatic acceleration of CHERI adoption into defence and aerospace commercial engagements, enabling the transformation of the industry NCSC, UKRI, DSIT and DARPA are all seeking.</ns2:abstractText></ns2:project>