Skip to content

ELASTIC: Efficient, portabLe And Secure orchesTration for reliable servICes. Revolutionizing connectivity with smart security

Website · Technology components · Demonstrators · CORDIS


About ELASTIC

Future 6G services will operate across a highly distributed edge-cloud continuum including IoT devices, industrial edge nodes, private infrastructures, and public clouds. ELASTIC addresses the need for secure, portable, and trustworthy service execution across these complex environments.

ELASTIC enables:

  • Secure and portable workload execution
  • Trustworthy distributed orchestration
  • Privacy-preserving edge-cloud services
  • Efficient operation across heterogeneous infrastructures
  • Resilient and adaptive 6G service deployment

Core technology pillars

Technology Role in ELASTIC
WebAssembly (Wasm) Lightweight and portable execution
eBPF High-performance observability and communication
Confidential Computing Protected processing in trusted environments
Remote Attestation Verification of infrastructure trust before execution
Serverless orchestration Adaptive deployment from cloud to far edge

Demonstrators

ELASTIC validates its vision through two demonstrators and 27 technology components.

Demonstrator 1 — Smart Connected Factory of the Future Demonstrator 2 — Privacy-Preserving Cloud Migration
Goal Validates a secure and scalable IoT Data Fabric for future industrial environments, enabling trusted data processing and intelligent orchestration across distributed edge-cloud infrastructures. Validates the secure migration and execution of sensitive enterprise services across cloud-edge infrastructures using confidential computing, attestation, and trusted orchestration.
Scenarios Predictive maintenance · Cross-factory data sharing through federated learning Badge Request Tool (BRT): migration of a sensitive enterprise application managing employee identity and access information
Led by Ericsson Finland Thales DIS

ELASTIC Architecture & Innovation Ecosystem

ELASTIC introduces a modular architecture for secure and resource-efficient orchestration of 6G services across the cloud-edge continuum.

The framework brings together interoperable technologies for trustworthy execution, intelligent orchestration, confidential computing, observability, and secure communication across heterogeneous infrastructures.

Five functional blocks

Functional blockWhat it providesComponentsOpen source
Block 1
Orchestration
Adaptive workload management across distributed edge-cloud infrastructures.74
Block 2
Isolation & Confidentiality
Secure workload isolation and confidential execution using WebAssembly and Trusted Execution Environments.75
Block 3
Communication
Efficient, low-latency communication for distributed services and edge-cloud coordination.33
Block 4
Monitoring & Detection
Runtime observability, performance monitoring, and AI-driven security detection.52
Block 5
Trust & Access Control
Remote attestation, policy enforcement, access control, and zero-trust mechanisms.51

Through these five blocks, ELASTIC develops 27 interoperable technology components supporting secure, portable, and trustworthy service execution for future 6G ecosystems.

Technology components

All 27 ELASTIC technology components are listed below, grouped by functional block. 15 are open source (14 with public code today, 1 to be released soon). For the other 12, contact the partner that develops them; their contact details are given on each component's entry.

ComponentPartnerAvailabilityCodeDocs
Block 1: Orchestration
Propeller OrchestratorAbstract MachinesOpen sourceRepoDocs
Wasm-operatorimecOpen sourceRepoPaper
Federated Learning as a ServiceTelefónica Innovación DigitalAccess on request——
Federated Learning ToolboxZentrix LabAccess on request—Info
Light-weight Security Orchestrator for Edge DevicesThales SIXAccess on request——
TEE Software Management AgentUltravioletOpen sourceRepoDocs
Reliable Enclave Migration ProtocolsAalto UniversityOpen sourceRepo—
Block 2: Isolation & Confidentiality
Data Protection at Rest at the Edge with TEE SolutionThales SIXAccess on request——
WasmHAL-Trust (TEEHAL)Lund UniversityOpen sourceRepo—
WASI SecurityimecOpen sourceRepo—
Automatic MAC Profiles for Wasm Runtime ContainersLund UniversityOpen sourceRepoDocs
WasmHAL Hardware SDKimecOpen sourceRepo—
Static eBPF Code Security Analyser (Pretty Verifier)Politecnico di TorinoOpen sourceRepoPaper
WITCHCRAFT: A WebAssembly Component Hooking FrameworkEricsson FinlandAccess on request——
Block 3: Communication
Accelerated Microservices InterconnectionPolitecnico di TorinoOpen sourceRepo—
eBPF Distributed State SynchronisationPolitecnico di TorinoOpen sourceRepo—
Static Analysis of Interaction between Wasm ModulesAalto UniversityOpen source, to be releasedSoon—
Block 4: Monitoring & Detection
NETTOPolitecnico di TorinoOpen sourceRepoPaper
Observability Framework for Serverless WorkloadsEricsson FinlandAccess on request—Info
Artificial Intelligence Intrusion Detection SystemTechnical University of CreteAccess on request——
Lightweight Hardware-based Cryptography ModuleTechnical University of CreteAccess on request——
Mobility Attack Robust IoT Resource Allocation ModelLund UniversityOpen sourceRepoPaper
Block 5: Trust & Access Control
Remote Attestations PlatformThales DISAccess on request——
Key Broker ServiceThales DISAccess on request——
Multi-platform Attestation ComponentEricsson FinlandAccess on request—Info
Lightweight ABAC SolutionThales SIXAccess on request——
WASI Flexibly-defined CapabilitiesAalto UniversityOpen sourceRepo—

Block 1: Orchestration

Block 1 · Orchestration

Adaptive workload management across distributed edge-cloud infrastructures.

Components in this block: Propeller Orchestrator · Wasm-operator · Federated Learning as a Service · Federated Learning Toolbox · Light-weight Security Orchestrator for Edge Devices · TEE Software Management Agent · Reliable Enclave Migration Protocols

Propeller Orchestrator

Open source

Cloud-to-IoT lightweight orchestration

Propeller enables secure and lightweight orchestration of WebAssembly workloads across distributed edge-cloud and IoT environments, including constrained and resource-limited devices.

  • Kubernetes integration via operator
  • WebAssembly-native deployment
  • Real-time FaaS execution
  • Event-driven service management
  • Ultra-lightweight footprint
  • IoT and microcontroller support
  • Low-latency distributed services
  • Secure cloud-edge deployment

Propeller is used in both ELASTIC Demonstrator 1 (6G IoT data fabric services) and Demonstrator 2 (secure workload migration across trust boundaries).

Repository: https://github.com/absmach/propeller
Documentation: https://propeller.absmach.eu/docs
Partner: Abstract Machines


Wasm-operator

Open source

Efficient WebAssembly orchestration for Kubernetes

Wasm-operator enables Kubernetes operators to run as event-based serverless functions in WebAssembly, reducing memory usage and improving efficiency in low-resource environments.

  • Kubernetes operator optimisation
  • Reduced memory footprint
  • WebAssembly-based runtime efficiency
  • Compatibility with kube-rs operators

Repository: https://github.com/idlab-discover/wasm-operator
Paper: https://doi.org/10.48550/arXiv.2209.01077
Partner: imec


Federated Learning as a Service

Access on request

Privacy-preserving machine learning across the computing continuum

FLaaS enables collaborative machine learning across the computing continuum without centralising raw data, supporting privacy-preserving AI in heterogeneous environments.

  • Hybrid federated and split learning as a service
  • Machine learning training on constrained devices
  • Privacy-preserving and TEE-enhanced secure model training
  • Lower adoption barrier for distributed machine learning

Partner: Telefónica Innovación Digital
Contact: Fionn Mc Inerney (fionn.mcinerney@telefonica.com)


Federated Learning Toolbox

Access on request

Privacy-preserving collaborative AI across distributed environments

The Federated Learning Toolbox enables organisations to collaboratively train AI models across distributed industrial environments while keeping sensitive data local. The framework supports scalable and portable AI execution across heterogeneous cloud and edge systems.

  • Privacy-preserving AI training without raw data sharing
  • Collaborative analytics across distributed industrial environments
  • Portable execution across heterogeneous cloud and edge infrastructures
  • Modular and scalable orchestration of federated AI workflows
  • Support for secure cross-organisational AI collaboration

More information: https://zentrixlab.com/
Partner: Zentrix Lab
Contact: office@zentrixlab.eu


Light-weight Security Orchestrator for Edge Devices

Access on request

Security orchestration at the edge

This component manages and deploys WebAssembly security functions according to security policies and SSLAs, enabling adaptive protection across edge and cloud environments.

  • Lightweight security orchestration
  • Policy-driven workload protection
  • SSLA-aware security enforcement
  • Dynamic adaptation to threats
  • Security for constrained edge devices

Partner: Thales SIX
Contact: Dhouha Ayed (dhouha.ayed@thalesgroup.com)


TEE Software Management Agent

Open source

Secure workload lifecycle management inside TEEs

The TEE Software Management Agent supports secure execution, attestation, cryptographic handling, and policy enforcement for sensitive workloads running inside Trusted Execution Environments.

  • Trusted workload execution enablement
  • Secure enclave lifecycle management
  • Remote attestation support
  • Propeller Orchestrator integration
  • Security policy enforcement

Repository: https://github.com/absmach/propeller/tree/main/proplet
Documentation: https://propeller.absmach.eu/docs/tee
Guide — Run inside a TEE: https://github.com/absmach/propeller/blob/main/proplet/README.md#run-inside-a-tee
Partner: Ultraviolet


Reliable Enclave Migration Protocols

Open source

Fault-tolerant migration for confidential workloads

This component enables reliable migration of sensitive resources between TEEs, ensuring that protected workloads can move securely without data loss or duplication.

  • Atomic migration between platforms: No doubt as to who is responsible for a migrated resource after-the-fact
  • Accountability: System operators can act confidently once migration completes, since they can prove that the other node will receive the same result
  • Performance: Optimistic protocol allows migration to proceed without any external coordination nodes unless a problem occurs
  • Fault-tolerance: Coordination infrastructure can be replicated to avoid single points of failure

Repository: https://github.com/elasticproject-eu/corndog
Partner: Aalto University

↑ Back to component overview


Block 2: Isolation & Confidentiality

Block 2 · Isolation & Confidentiality

Secure workload isolation and confidential execution using WebAssembly and Trusted Execution Environments.

Components in this block: Data Protection at Rest at the Edge with TEE Solution · WasmHAL-Trust (TEEHAL) · WASI Security · Automatic MAC Profiles for Wasm Runtime Containers · WasmHAL Hardware SDK · Static eBPF Code Security Analyser (Pretty Verifier) · WITCHCRAFT: A WebAssembly Component Hooking Framework

Data Protection at Rest at the Edge with TEE Solution

Access on request

Transparent encryption for secure edge workloads

This component protects data at rest generated by WebAssembly workloads running inside TEEs, enabling transparent encryption for sensitive edge environments.

  • Edge-ready data protection
  • Data-at-rest confidentiality on untrusted hosts
  • Protection for WASM workloads
  • TEE-based secure processing
  • Hardware root-of-trust integration

Partner: Thales SIX
Contact: Louis Cailliot (louis.cailliot@thalesgroup.com)


WasmHAL-Trust (TEEHAL)

Open source

Portable WebAssembly execution across confidential environments

WasmHAL-Trust provides a Hardware Abstraction Layer (HAL) for secure and portable WebAssembly workloads across different Trusted Execution Environments.

  • WASI-compliant HAL interface
  • Portable confidential workloads across different Trusted Execution Environments (TEEs)
  • Multi-TEE (AMD SEV-SNP, Intel TDX) execution support
  • Protected storage capabilities
  • Attestation interface
  • Cryptographic operations interface
  • Secure migration support

Repository: https://github.com/elasticproject-eu/wasmhal
Partner: Lund University


WASI Security

Open source

Standardised access control policies for WebAssembly workloads

WASI Security defines a portable policy mechanism for enforcing fine-grained permissions across WebAssembly runtimes and orchestration environments.

  • Standardised WASI security policies
  • Fine-grained workload permissions
  • Secure device and file access

Repository: https://github.com/idlab-discover/masters-wasi-security/tree/blocking_rules_policy_file
Partner: imec


Automatic MAC Profiles for Wasm Runtime Containers

Open source

Automated least-privilege protection for WebAssembly workloads

This component automatically generates restrictive Mandatory Access Control profiles in compliance with the ELASTIC Wasm HAL for WebAssembly workloads, reducing privileges and minimising attack surfaces.

  • Automatic MAC profile generation
  • Least-privilege enforcement
  • Reduced attack surface
  • Wasm workload profiling
  • Low configuration effort
  • Runtime protection automation

Repository: https://github.com/syafiq/enforcement-service
Getting started: https://github.com/syafiq/enforcement-service/blob/HEAD/GETTING_STARTED.md
Architecture: https://github.com/syafiq/enforcement-service/blob/HEAD/ARCHITECTURE.md
Partner: Lund University


WasmHAL Hardware SDK

Open source

Secure hardware access for WebAssembly applications

WasmHAL Hardware SDK enables WebAssembly applications to securely access hardware interfaces across platforms through standardised APIs and runtime extensions.

  • Sandboxed device drivers
  • USB, I2C, SPI & GPIO support
  • Supporting multi-decade support periods
  • Microcontrollers & embedded Linux

WASI standardisation proposals (WebAssembly System Interface)

Interface Proposal Phase Implementation
I2C wasi-i2c Phase 2 i2c-wasm-components (in collaboration with Siemens)
USB wasi-usb Phase 1 usb-wasm
GPIO wasi-gpio Phase 1 masters-jarno-vanruymbeke
SPI SPI WIT definitions Phase 1 —

Repository: https://github.com/idlab-discover/usb-wasm
Partner: imec


Static eBPF Code Security Analyser (Pretty Verifier)

Open source

Early security feedback for eBPF developers

This analyser detects security issues in eBPF C source code before deployment, helping developers understand and fix issues earlier in the development process.

  • Security-aware eBPF development
  • Clear verifier error explanations
  • Developer-friendly fix guidance
  • Reduced debugging time

Repository: https://github.com/netgroup-polito/pretty-verifier
Paper (preprint): https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6727186
Partner: Politecnico di Torino


WITCHCRAFT: A WebAssembly Component Hooking Framework

Access on request

Granular access control, observability, and custom logic for WebAssembly Component Model applications

This framework enables dynamic interception of WebAssembly Component function calls at runtime, supporting access control enforcement, observability, and arbitrary logic injection without modifying guest binaries.

  • Function call interception at component boundaries
  • Runtime-swappable interception logic compiled as native dynamic libraries
  • Argument inspection and modification, call bypass, and termination
  • WIT-based Rust-native hook development kit
  • Runtime interaction and persistent state across invocations
  • Built on Wasmtime with Canonical ABI conformance

Partner: Ericsson Finland
Contact: Joonas Bjork (joonas.bjork@ericsson.com), Rajat Kandoi (rajat.kandoi@ericsson.com)

↑ Back to component overview


Block 3: Communication

Block 3 · Communication

Efficient, low-latency communication for distributed services and edge-cloud coordination.

Components in this block: Accelerated Microservices Interconnection · eBPF Distributed State Synchronisation · Static Analysis of Interaction between Wasm Modules

Accelerated Microservices Interconnection

Open source

High-performance networking for cloud-native services

This component accelerates TCP communication within and between cluster nodes, improving throughput and reducing latency for micro services-based infrastructures.

  • Ready for cloud-native deployments
  • Intra- and inter-node acceleration
  • eBPF and RDMA network optimizations
  • Higher throughput and lower latency for TCP traffic

Repository: https://github.com/miolad/linux-tcpless
Partner: Politecnico di Torino


eBPF Distributed State Synchronisation

Open source

Ultra-low-latency eBPF state sharing across servers

This component extends eBPF maps across networked hosts, enabling fast state synchronisation between distributed eBPF probes.

  • Sub-100µs target delay on data-center networks
  • Eventual-consistency data replication
  • Unlimited horizontal scalability
  • Supports hash maps, more to come
  • No kernel modifications required

Repository: https://github.com/miolad/ebpf-distributed-htab
Partner: Politecnico di Torino


Static Analysis of Interaction between Wasm Modules

Open source, to be released

Trust verification for distributed WebAssembly applications

This component analyses interactions between WebAssembly modules before runtime, supporting secure composition and attestation of distributed serverless applications.

  • Static analysis of WebAssembly components to obtain deployment-independent module-to-module connections
  • Attestation protocol to establish identity of whole application deployment, not just individual TEEs
  • Attested RPC between Wasm components located on different machines
  • Incorporating WebAssembly into the RATS ecosystem

Repository (code to be released): https://github.com/elasticproject-eu/wasm-attestation
Partner: Aalto University
Contact: Parsa Sadri Sinaki (parsa.sadrisinaki@aalto.fi)

↑ Back to component overview


Block 4: Monitoring & Detection

Block 4 · Monitoring & Detection

Runtime observability, performance monitoring, and AI-driven security detection.

Components in this block: NETTO · Observability Framework for Serverless Workloads · Artificial Intelligence Intrusion Detection System · Lightweight Hardware-based Cryptography Module · Mobility Attack Robust IoT Resource Allocation Model

NETTO

Open source

Real-time visibility into Linux network stack cost

NETTO measures the CPU overhead of Linux network functions in real-time, helping operators identify bottlenecks and optimize network performance.

  • Real-time, low-overhead network profiling
  • eBPF+perf instrumentation
  • Userspace data analysis
  • Intuitive stack trace visualisation with Grafana Pyroscope
  • Bottleneck identification

Repository: https://github.com/miolad/netto
Paper (Netdev 0x17): https://iris.polito.it/retrieve/handle/11583/2992332/086c1e80-0c27-4850-91b9-a958bd405edd/netdev-0x17-paper34-talk-paper.pdf
Partner: Politecnico di Torino


Observability Framework for Serverless Workloads

Access on request

Operational visibility for WebAssembly serverless environments

This framework provides targeted observability for WebAssembly-based serverless workloads, supporting performance monitoring.

  • Observability for WASM based serverless workloads (Spinkube)
  • Based on eBPF uprobe mechanism, possible to extend for non-WASM workloads
  • Rule-based data collection using ring buffers
  • Kafka-based data output using OpenTelemetry-inspired format
  • Low-overhead observability using Rust based userspace data collector

More information: https://youtu.be/5P1HITjYWmE
Partner: Ericsson Finland
Contact: Miika Komu (miika.komu@ericsson.com)


Artificial Intelligence Intrusion Detection System

Access on request

AI-driven cybersecurity for edge and 6G infrastructures

This component provides AI-enhanced and hardware-accelerated intrusion detection for real-time threat monitoring and adaptive cybersecurity across edge, IoT, cloud and 5G/6G ecosystems.

  • AI-driven intrusion detection
  • Adaptive anomaly & threat detection
  • Hardware-accelerated low-latency monitoring
  • Continuous learning & signature refinement
  • Edge, IoT, cloud & 5G/6G security support

Partner: Technical University of Crete
Contact: Grigorios Chrysos (gxrysos@tuc.gr)


Lightweight Hardware-based Cryptography Module

Access on request

Hardware-accelerated lightweight cryptography

This component provides hardware-accelerated lightweight cryptography for secure, energy-efficient and real-time communications across edge, IoT and next-generation 5G/6G ecosystems.

  • Real-time encryption and authentication
  • Energy-efficient lightweight cryptography
  • Advanced data integrity protection
  • Secure edge, IoT & 5G/6G communication

Partner: Technical University of Crete
Contact: Grigorios Chrysos (gxrysos@tuc.gr)


Mobility Attack Robust IoT Resource Allocation Model

Open source

Robust mobility prediction for secure 6G networks

This component uses AutoML to provide robust mobility under mobility attack conditions for future 6G network analytics and resource allocation.

  • Mobility attack resilience
  • Secure mobility prediction
  • AutoML-based modelling
  • NWDAF compatible
  • Open simulation framework
  • Assist 6G resource planning
  • Research-ready mobility datasets

Repository: https://github.com/nwdaf-research/dataset-attack
Paper (FMEC 2024, open access): https://zenodo.org/records/13969430
Partner: Lund University

↑ Back to component overview


Block 5: Trust & Access Control

Block 5 · Trust & Access Control

Remote attestation, policy enforcement, access control, and zero-trust mechanisms.

Components in this block: Remote Attestations Platform · Key Broker Service · Multi-platform Attestation Component · Lightweight ABAC Solution · WASI Flexibly-defined Capabilities

Remote Attestations Platform

Access on request

Hardware-agnostic trust verification for confidential computing

This platform supports remote attestation across multiple cloud providers and TEE architectures, enabling trust verification before sensitive workloads are executed.

  • Multi-cloud attestation support
  • Intel TDX and ARM Trust Zone support
  • Hardware-agnostic verification
  • Trust before execution
  • Confidential computing enablement
  • Multi-tenant security assurance
  • Public cloud trust validation
  • Interoperability across TEEs

Partner: Thales DIS
Contact: Volker Breuer (volker.breuer@thalesgroup.com)


Key Broker Service

Access on request

Attestation-based key release for secure workload migration

The Key Broker Service releases cryptographic keys only after successful attestation, enabling secure migration and execution of sensitive workloads in trusted environments.

  • Key release after attestation
  • Secure workload migration
  • BYOK/HYOK support potential
  • Customer-controlled cryptographic keys
  • Public cloud confidentiality
  • Secure secret provisioning
  • Compliance-aware key management
  • Trust-linked cloud execution

Partner: Thales DIS
Contact: Volker Breuer (volker.breuer@thalesgroup.com)


Multi-platform Attestation Component

Access on request

Unified attestation across heterogeneous platforms

This component verifies remote attestation evidence from multiple different TEE platforms through a unified mechanism, supporting trust establishment across diverse infrastructures.

  • TEE vendor agnostic remote attestation
  • Confidential Computing interoperability
  • Unified multi-platform verification interface
  • Attestation based on WebAssembly components
  • Decoupling of TEE platform and verifier lifecycles
  • Reduced TEE vendor and verification service dependency
  • Data Fabric trust establishment support
  • Data producer/consumer attestation

More information: https://youtu.be/cs7SY35RHa4
Partner: Ericsson Finland
Contact: Jimmy Kjällman (jimmy.kjallman@ericsson.com)


Lightweight ABAC Solution

Access on request

Fine-grained access control for secure edge environments

The Lightweight ABAC solution enforces attribute-based access control policies for WebAssembly orchestration and runtime interactions in resource-constrained environments.

  • Light-weight attribute-based access control
  • Fine-grained policy enforcement
  • Zero-trust architecture alignment
  • WASM container protection
  • Edge-ready security policies

Partner: Thales SIX
Contact: Cyril Dangerville (cyril.dangerville@thalesgroup.com)


WASI Flexibly-defined Capabilities

Open source

Custom access control policies for WebAssembly applications

This component enables easy instrumentation of existing WebAssembly applications with custom logic.

  • Easily insert observability, access control, or compatibility layers into WebAssembly components
  • Automatically transform WAC scripts without manual effort
  • Shims are isolated from other code by the WebAssembly sandbox
  • Auto-generate shim scaffolds for easy development

Repository: https://github.com/elasticproject-eu/wacky
Partner: Aalto University

↑ Back to component overview


Partners

Technical University of Crete
Technical University of Crete
Ericsson
Ericsson
Telefónica Innovación Digital
Telefónica Innovación Digital
Thales
Thales
imec
imec
Ultraviolet
Ultraviolet
Aalto University
Aalto University
Lund University
Lund University
Abstract Machines
Abstract Machines
Zentrix Lab
Zentrix Lab
Politecnico di Torino
Politecnico di Torino

Funding information

ELASTIC project has received funding from the Smart Networks and Services Joint Undertaking (SNS JU) under the European Union’s Horizon Europe research and innovation programme under Grant Agreement No 101139067. Views and opinions expressed are however those of the authors only and do not necessarily reflect those of the European Union. Neither the European Union nor the granting authority can be held responsible for them.

Popular repositories Loading

  1. wasmhal wasmhal Public

    Rust 4 3

  2. trustmee-artifact trustmee-artifact Public

    Rust 2

  3. .github .github Public

  4. wasmtime wasmtime Public

    Forked from bytecodealliance/wasmtime

    A lightweight WebAssembly runtime that is fast, secure, and standards-compliant

    Rust

  5. trustmee trustmee Public

    Rust

  6. trustmee-lib trustmee-lib Public

    Rust 1

Repositories

Showing 10 of 15 repositories

Top languages

Loading…

Most used topics

Loading…