Website · Technology components · Demonstrators · CORDIS
Future 6G services will operate across a highly distributed edge-cloud continuum including IoT devices, industrial edge nodes, private infrastructures, and public clouds. ELASTIC addresses the need for secure, portable, and trustworthy service execution across these complex environments.
ELASTIC enables:
- Secure and portable workload execution
- Trustworthy distributed orchestration
- Privacy-preserving edge-cloud services
- Efficient operation across heterogeneous infrastructures
- Resilient and adaptive 6G service deployment
| Technology | Role in ELASTIC |
|---|---|
| WebAssembly (Wasm) | Lightweight and portable execution |
| eBPF | High-performance observability and communication |
| Confidential Computing | Protected processing in trusted environments |
| Remote Attestation | Verification of infrastructure trust before execution |
| Serverless orchestration | Adaptive deployment from cloud to far edge |
ELASTIC validates its vision through two demonstrators and 27 technology components.
| Demonstrator 1 — Smart Connected Factory of the Future | Demonstrator 2 — Privacy-Preserving Cloud Migration | |
|---|---|---|
| Goal | Validates a secure and scalable IoT Data Fabric for future industrial environments, enabling trusted data processing and intelligent orchestration across distributed edge-cloud infrastructures. | Validates the secure migration and execution of sensitive enterprise services across cloud-edge infrastructures using confidential computing, attestation, and trusted orchestration. |
| Scenarios | Predictive maintenance · Cross-factory data sharing through federated learning | Badge Request Tool (BRT): migration of a sensitive enterprise application managing employee identity and access information |
| Led by | Ericsson Finland | Thales DIS |
ELASTIC introduces a modular architecture for secure and resource-efficient orchestration of 6G services across the cloud-edge continuum.
The framework brings together interoperable technologies for trustworthy execution, intelligent orchestration, confidential computing, observability, and secure communication across heterogeneous infrastructures.
| Functional block | What it provides | Components | Open source |
|---|---|---|---|
Orchestration | Adaptive workload management across distributed edge-cloud infrastructures. | 7 | 4 |
Isolation & Confidentiality | Secure workload isolation and confidential execution using WebAssembly and Trusted Execution Environments. | 7 | 5 |
Communication | Efficient, low-latency communication for distributed services and edge-cloud coordination. | 3 | 3 |
Monitoring & Detection | Runtime observability, performance monitoring, and AI-driven security detection. | 5 | 2 |
Trust & Access Control | Remote attestation, policy enforcement, access control, and zero-trust mechanisms. | 5 | 1 |
Through these five blocks, ELASTIC develops 27 interoperable technology components supporting secure, portable, and trustworthy service execution for future 6G ecosystems.
All 27 ELASTIC technology components are listed below, grouped by functional block. 15 are open source (14 with public code today, 1 to be released soon). For the other 12, contact the partner that develops them; their contact details are given on each component's entry.
Adaptive workload management across distributed edge-cloud infrastructures.
Components in this block: Propeller Orchestrator · Wasm-operator · Federated Learning as a Service · Federated Learning Toolbox · Light-weight Security Orchestrator for Edge Devices · TEE Software Management Agent · Reliable Enclave Migration Protocols
Cloud-to-IoT lightweight orchestration
Propeller enables secure and lightweight orchestration of WebAssembly workloads across distributed edge-cloud and IoT environments, including constrained and resource-limited devices.
- Kubernetes integration via operator
- WebAssembly-native deployment
- Real-time FaaS execution
- Event-driven service management
- Ultra-lightweight footprint
- IoT and microcontroller support
- Low-latency distributed services
- Secure cloud-edge deployment
Propeller is used in both ELASTIC Demonstrator 1 (6G IoT data fabric services) and Demonstrator 2 (secure workload migration across trust boundaries).
Repository: https://github.com/absmach/propeller
Documentation: https://propeller.absmach.eu/docs
Partner: Abstract Machines
Efficient WebAssembly orchestration for Kubernetes
Wasm-operator enables Kubernetes operators to run as event-based serverless functions in WebAssembly, reducing memory usage and improving efficiency in low-resource environments.
- Kubernetes operator optimisation
- Reduced memory footprint
- WebAssembly-based runtime efficiency
- Compatibility with kube-rs operators
Repository: https://github.com/idlab-discover/wasm-operator
Paper: https://doi.org/10.48550/arXiv.2209.01077
Partner: imec
Privacy-preserving machine learning across the computing continuum
FLaaS enables collaborative machine learning across the computing continuum without centralising raw data, supporting privacy-preserving AI in heterogeneous environments.
- Hybrid federated and split learning as a service
- Machine learning training on constrained devices
- Privacy-preserving and TEE-enhanced secure model training
- Lower adoption barrier for distributed machine learning
Partner: Telefónica Innovación Digital
Contact: Fionn Mc Inerney (fionn.mcinerney@telefonica.com)
Privacy-preserving collaborative AI across distributed environments
The Federated Learning Toolbox enables organisations to collaboratively train AI models across distributed industrial environments while keeping sensitive data local. The framework supports scalable and portable AI execution across heterogeneous cloud and edge systems.
- Privacy-preserving AI training without raw data sharing
- Collaborative analytics across distributed industrial environments
- Portable execution across heterogeneous cloud and edge infrastructures
- Modular and scalable orchestration of federated AI workflows
- Support for secure cross-organisational AI collaboration
More information: https://zentrixlab.com/
Partner: Zentrix Lab
Contact: office@zentrixlab.eu
Security orchestration at the edge
This component manages and deploys WebAssembly security functions according to security policies and SSLAs, enabling adaptive protection across edge and cloud environments.
- Lightweight security orchestration
- Policy-driven workload protection
- SSLA-aware security enforcement
- Dynamic adaptation to threats
- Security for constrained edge devices
Partner: Thales SIX
Contact: Dhouha Ayed (dhouha.ayed@thalesgroup.com)
Secure workload lifecycle management inside TEEs
The TEE Software Management Agent supports secure execution, attestation, cryptographic handling, and policy enforcement for sensitive workloads running inside Trusted Execution Environments.
- Trusted workload execution enablement
- Secure enclave lifecycle management
- Remote attestation support
- Propeller Orchestrator integration
- Security policy enforcement
Repository: https://github.com/absmach/propeller/tree/main/proplet
Documentation: https://propeller.absmach.eu/docs/tee
Guide — Run inside a TEE: https://github.com/absmach/propeller/blob/main/proplet/README.md#run-inside-a-tee
Partner: Ultraviolet
Fault-tolerant migration for confidential workloads
This component enables reliable migration of sensitive resources between TEEs, ensuring that protected workloads can move securely without data loss or duplication.
- Atomic migration between platforms: No doubt as to who is responsible for a migrated resource after-the-fact
- Accountability: System operators can act confidently once migration completes, since they can prove that the other node will receive the same result
- Performance: Optimistic protocol allows migration to proceed without any external coordination nodes unless a problem occurs
- Fault-tolerance: Coordination infrastructure can be replicated to avoid single points of failure
Repository: https://github.com/elasticproject-eu/corndog
Partner: Aalto University
Secure workload isolation and confidential execution using WebAssembly and Trusted Execution Environments.
Components in this block: Data Protection at Rest at the Edge with TEE Solution · WasmHAL-Trust (TEEHAL) · WASI Security · Automatic MAC Profiles for Wasm Runtime Containers · WasmHAL Hardware SDK · Static eBPF Code Security Analyser (Pretty Verifier) · WITCHCRAFT: A WebAssembly Component Hooking Framework
Transparent encryption for secure edge workloads
This component protects data at rest generated by WebAssembly workloads running inside TEEs, enabling transparent encryption for sensitive edge environments.
- Edge-ready data protection
- Data-at-rest confidentiality on untrusted hosts
- Protection for WASM workloads
- TEE-based secure processing
- Hardware root-of-trust integration
Partner: Thales SIX
Contact: Louis Cailliot (louis.cailliot@thalesgroup.com)
Portable WebAssembly execution across confidential environments
WasmHAL-Trust provides a Hardware Abstraction Layer (HAL) for secure and portable WebAssembly workloads across different Trusted Execution Environments.
- WASI-compliant HAL interface
- Portable confidential workloads across different Trusted Execution Environments (TEEs)
- Multi-TEE (AMD SEV-SNP, Intel TDX) execution support
- Protected storage capabilities
- Attestation interface
- Cryptographic operations interface
- Secure migration support
Repository: https://github.com/elasticproject-eu/wasmhal
Partner: Lund University
Standardised access control policies for WebAssembly workloads
WASI Security defines a portable policy mechanism for enforcing fine-grained permissions across WebAssembly runtimes and orchestration environments.
- Standardised WASI security policies
- Fine-grained workload permissions
- Secure device and file access
Repository: https://github.com/idlab-discover/masters-wasi-security/tree/blocking_rules_policy_file
Partner: imec
Automated least-privilege protection for WebAssembly workloads
This component automatically generates restrictive Mandatory Access Control profiles in compliance with the ELASTIC Wasm HAL for WebAssembly workloads, reducing privileges and minimising attack surfaces.
- Automatic MAC profile generation
- Least-privilege enforcement
- Reduced attack surface
- Wasm workload profiling
- Low configuration effort
- Runtime protection automation
Repository: https://github.com/syafiq/enforcement-service
Getting started: https://github.com/syafiq/enforcement-service/blob/HEAD/GETTING_STARTED.md
Architecture: https://github.com/syafiq/enforcement-service/blob/HEAD/ARCHITECTURE.md
Partner: Lund University
Secure hardware access for WebAssembly applications
WasmHAL Hardware SDK enables WebAssembly applications to securely access hardware interfaces across platforms through standardised APIs and runtime extensions.
- Sandboxed device drivers
- USB, I2C, SPI & GPIO support
- Supporting multi-decade support periods
- Microcontrollers & embedded Linux
WASI standardisation proposals (WebAssembly System Interface)
| Interface | Proposal | Phase | Implementation |
|---|---|---|---|
| I2C | wasi-i2c | Phase 2 | i2c-wasm-components (in collaboration with Siemens) |
| USB | wasi-usb | Phase 1 | usb-wasm |
| GPIO | wasi-gpio | Phase 1 | masters-jarno-vanruymbeke |
| SPI | SPI WIT definitions | Phase 1 | — |
Repository: https://github.com/idlab-discover/usb-wasm
Partner: imec
Early security feedback for eBPF developers
This analyser detects security issues in eBPF C source code before deployment, helping developers understand and fix issues earlier in the development process.
- Security-aware eBPF development
- Clear verifier error explanations
- Developer-friendly fix guidance
- Reduced debugging time
Repository: https://github.com/netgroup-polito/pretty-verifier
Paper (preprint): https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6727186
Partner: Politecnico di Torino
Granular access control, observability, and custom logic for WebAssembly Component Model applications
This framework enables dynamic interception of WebAssembly Component function calls at runtime, supporting access control enforcement, observability, and arbitrary logic injection without modifying guest binaries.
- Function call interception at component boundaries
- Runtime-swappable interception logic compiled as native dynamic libraries
- Argument inspection and modification, call bypass, and termination
- WIT-based Rust-native hook development kit
- Runtime interaction and persistent state across invocations
- Built on Wasmtime with Canonical ABI conformance
Partner: Ericsson Finland
Contact: Joonas Bjork (joonas.bjork@ericsson.com), Rajat Kandoi (rajat.kandoi@ericsson.com)
Efficient, low-latency communication for distributed services and edge-cloud coordination.
Components in this block: Accelerated Microservices Interconnection · eBPF Distributed State Synchronisation · Static Analysis of Interaction between Wasm Modules
High-performance networking for cloud-native services
This component accelerates TCP communication within and between cluster nodes, improving throughput and reducing latency for micro services-based infrastructures.
- Ready for cloud-native deployments
- Intra- and inter-node acceleration
- eBPF and RDMA network optimizations
- Higher throughput and lower latency for TCP traffic
Repository: https://github.com/miolad/linux-tcpless
Partner: Politecnico di Torino
Ultra-low-latency eBPF state sharing across servers
This component extends eBPF maps across networked hosts, enabling fast state synchronisation between distributed eBPF probes.
- Sub-100µs target delay on data-center networks
- Eventual-consistency data replication
- Unlimited horizontal scalability
- Supports hash maps, more to come
- No kernel modifications required
Repository: https://github.com/miolad/ebpf-distributed-htab
Partner: Politecnico di Torino
Trust verification for distributed WebAssembly applications
This component analyses interactions between WebAssembly modules before runtime, supporting secure composition and attestation of distributed serverless applications.
- Static analysis of WebAssembly components to obtain deployment-independent module-to-module connections
- Attestation protocol to establish identity of whole application deployment, not just individual TEEs
- Attested RPC between Wasm components located on different machines
- Incorporating WebAssembly into the RATS ecosystem
Repository (code to be released): https://github.com/elasticproject-eu/wasm-attestation
Partner: Aalto University
Contact: Parsa Sadri Sinaki (parsa.sadrisinaki@aalto.fi)
Runtime observability, performance monitoring, and AI-driven security detection.
Components in this block: NETTO · Observability Framework for Serverless Workloads · Artificial Intelligence Intrusion Detection System · Lightweight Hardware-based Cryptography Module · Mobility Attack Robust IoT Resource Allocation Model
Real-time visibility into Linux network stack cost
NETTO measures the CPU overhead of Linux network functions in real-time, helping operators identify bottlenecks and optimize network performance.
- Real-time, low-overhead network profiling
- eBPF+perf instrumentation
- Userspace data analysis
- Intuitive stack trace visualisation with Grafana Pyroscope
- Bottleneck identification
Repository: https://github.com/miolad/netto
Paper (Netdev 0x17): https://iris.polito.it/retrieve/handle/11583/2992332/086c1e80-0c27-4850-91b9-a958bd405edd/netdev-0x17-paper34-talk-paper.pdf
Partner: Politecnico di Torino
Operational visibility for WebAssembly serverless environments
This framework provides targeted observability for WebAssembly-based serverless workloads, supporting performance monitoring.
- Observability for WASM based serverless workloads (Spinkube)
- Based on eBPF uprobe mechanism, possible to extend for non-WASM workloads
- Rule-based data collection using ring buffers
- Kafka-based data output using OpenTelemetry-inspired format
- Low-overhead observability using Rust based userspace data collector
More information: https://youtu.be/5P1HITjYWmE
Partner: Ericsson Finland
Contact: Miika Komu (miika.komu@ericsson.com)
AI-driven cybersecurity for edge and 6G infrastructures
This component provides AI-enhanced and hardware-accelerated intrusion detection for real-time threat monitoring and adaptive cybersecurity across edge, IoT, cloud and 5G/6G ecosystems.
- AI-driven intrusion detection
- Adaptive anomaly & threat detection
- Hardware-accelerated low-latency monitoring
- Continuous learning & signature refinement
- Edge, IoT, cloud & 5G/6G security support
Partner: Technical University of Crete
Contact: Grigorios Chrysos (gxrysos@tuc.gr)
Hardware-accelerated lightweight cryptography
This component provides hardware-accelerated lightweight cryptography for secure, energy-efficient and real-time communications across edge, IoT and next-generation 5G/6G ecosystems.
- Real-time encryption and authentication
- Energy-efficient lightweight cryptography
- Advanced data integrity protection
- Secure edge, IoT & 5G/6G communication
Partner: Technical University of Crete
Contact: Grigorios Chrysos (gxrysos@tuc.gr)
Robust mobility prediction for secure 6G networks
This component uses AutoML to provide robust mobility under mobility attack conditions for future 6G network analytics and resource allocation.
- Mobility attack resilience
- Secure mobility prediction
- AutoML-based modelling
- NWDAF compatible
- Open simulation framework
- Assist 6G resource planning
- Research-ready mobility datasets
Repository: https://github.com/nwdaf-research/dataset-attack
Paper (FMEC 2024, open access): https://zenodo.org/records/13969430
Partner: Lund University
Remote attestation, policy enforcement, access control, and zero-trust mechanisms.
Components in this block: Remote Attestations Platform · Key Broker Service · Multi-platform Attestation Component · Lightweight ABAC Solution · WASI Flexibly-defined Capabilities
Hardware-agnostic trust verification for confidential computing
This platform supports remote attestation across multiple cloud providers and TEE architectures, enabling trust verification before sensitive workloads are executed.
- Multi-cloud attestation support
- Intel TDX and ARM Trust Zone support
- Hardware-agnostic verification
- Trust before execution
- Confidential computing enablement
- Multi-tenant security assurance
- Public cloud trust validation
- Interoperability across TEEs
Partner: Thales DIS
Contact: Volker Breuer (volker.breuer@thalesgroup.com)
Attestation-based key release for secure workload migration
The Key Broker Service releases cryptographic keys only after successful attestation, enabling secure migration and execution of sensitive workloads in trusted environments.
- Key release after attestation
- Secure workload migration
- BYOK/HYOK support potential
- Customer-controlled cryptographic keys
- Public cloud confidentiality
- Secure secret provisioning
- Compliance-aware key management
- Trust-linked cloud execution
Partner: Thales DIS
Contact: Volker Breuer (volker.breuer@thalesgroup.com)
Unified attestation across heterogeneous platforms
This component verifies remote attestation evidence from multiple different TEE platforms through a unified mechanism, supporting trust establishment across diverse infrastructures.
- TEE vendor agnostic remote attestation
- Confidential Computing interoperability
- Unified multi-platform verification interface
- Attestation based on WebAssembly components
- Decoupling of TEE platform and verifier lifecycles
- Reduced TEE vendor and verification service dependency
- Data Fabric trust establishment support
- Data producer/consumer attestation
More information: https://youtu.be/cs7SY35RHa4
Partner: Ericsson Finland
Contact: Jimmy Kjällman (jimmy.kjallman@ericsson.com)
Fine-grained access control for secure edge environments
The Lightweight ABAC solution enforces attribute-based access control policies for WebAssembly orchestration and runtime interactions in resource-constrained environments.
- Light-weight attribute-based access control
- Fine-grained policy enforcement
- Zero-trust architecture alignment
- WASM container protection
- Edge-ready security policies
Partner: Thales SIX
Contact: Cyril Dangerville (cyril.dangerville@thalesgroup.com)
Custom access control policies for WebAssembly applications
This component enables easy instrumentation of existing WebAssembly applications with custom logic.
- Easily insert observability, access control, or compatibility layers into WebAssembly components
- Automatically transform WAC scripts without manual effort
- Shims are isolated from other code by the WebAssembly sandbox
- Auto-generate shim scaffolds for easy development
Repository: https://github.com/elasticproject-eu/wacky
Partner: Aalto University
![]() Technical University of Crete | ![]() Ericsson | ![]() Telefónica Innovación Digital | ![]() Thales |
![]() imec | Ultraviolet | ![]() Aalto University | ![]() Lund University |
![]() Abstract Machines | ![]() Zentrix Lab | ![]() Politecnico di Torino |
ELASTIC project has received funding from the Smart Networks and Services Joint Undertaking (SNS JU) under the European Union’s Horizon Europe research and innovation programme under Grant Agreement No 101139067. Views and opinions expressed are however those of the authors only and do not necessarily reflect those of the European Union. Neither the European Union nor the granting authority can be held responsible for them.










