Skip to content
    • About us
          • Digital Catapult is a deep tech innovation organisation driving business value by accelerating the application of advanced technologies.

            3,000

            Companies supported since 2018

            £555m

            Investment raised by startups since 2018

            20+

            Advanced technology facilities nationwide

    • Our ambition
          • Our ambition is to realise the practical application of deep tech through four interventions

            ambition-scale-deep-tech

            Enabling UK deep tech companies to scale

            ambition-improving-supply-chain

            Improving UK industrial supply chain resilience

            ambition-decarbonisation

            Driving industrial decarbonisation

            ambition-advancing-data

            Advancing UK development and use of data driven and open future networks

    • Our people
          • susan-bowen

            We are an organisation made up of almost 300 innovators.

            We pride ourselves on the skilled and talented people from varied backgrounds that make up our team – we harness the expertise, perspectives and connections of people of more than 40 nationalities, thereby bringing together a diversity of skills, experience and backgrounds.

            Susan Bowen

            CEO of Digital Catapult

    • Our places
    • Startups and scaleups
          • bfp cover

            Black Founders Programme

            The Black Founders Programme is an accelerator targeted at pre-seed or seed stage, Black-founded companies creating innovative products and services...
            ORCA-020

            Quantum Technology Programme

            Separating opportunity from hype to understand industry challenges that may be best solved by quantum computing.
    • Government and Public sector
          • 3d,Illustration,Of,Hydrogen,H2,Molecule,Model,-,Clean,Energy

            Hydrogen Innovation Programme

            Discover more about the the Hydrogen Innovation Initiative and the deployment of hydrogen technologies to address pressing energy and environmental...
            London,Office,Building,For,Network,And,Future,Concept

            Digitalising Energy Programme

            Energy Systems Catapult and Digital Catapult have partnered to explore the groundwork for a UK-wide initiative to accelerate a digitalised,...
          • Banner website digital twin 3

            UK Digital Twin Centre

            Delivered by Digital Catapult and funded by Belfast Region City Deal and Innovate UK, the UK Digital Twin Centre makes digital twins more accessible and meaningful in the UK. It actively enable industries and innovators to safely embrace, explore and realise their dynamic power.
            Find out more UK Digital Twin Centre
    • Corporates and Industry
          • Transparent,Clear,Colorful,Glass,Or,Liquid,Waves.,Neon,Pattern,Abstract

            Green Hydrogen Certifier

            This report looks at the Green Hydrogen Certifier - an end-to-end demonstration of a potential digital certification solution for hydrogen production...
    • Academia
    • Investors
          • bfp cover

            Black Founders Programme

            The Black Founders Programme is an accelerator targeted at pre-seed or seed stage, Black-founded companies creating innovative products and services...
    • Services
          • Bespoke software & data systems

            Developing proof-of-concept demonstrators to showcase the viability and benefit of deep tech solutions.

            Platform engineering service

            Designing, building and operating physical and digital facilities. Providing testbeds for deep tech discovery and experimentation.

            Technology & innovation consultancy

            Consultancy services helping organisations addresses market preparedness gaps, evaluate financial viability and navigate technology change management.

          • Acceleration programmes for business

            Creating acceleration programmes to support businesses.Helping them grow through mentorship, technology support, networking, and investment opportunities.

            Facilitating and convening

            Bringing together and developing ecosystems of companies to explore, test and demonstrate how deep tech works in practice.

    • Technologies
    • Facilities
    • Opportunities
          • newsletter

            Sign up to our newsletter

            sign up for alerts and be the first to know when new open calls are announced. Don’t miss your chance to stay informed and get involved!

    • Current interventions
          • ORCA-020

            Quantum Technology Programme

            Separating opportunity from hype to understand industry challenges that may be best solved by quantum computing.
          • Banner website digital twin 3

            UK Digital Twin Centre

            Delivered by Digital Catapult and funded by Belfast Region City Deal and Innovate UK, the UK Digital Twin Centre makes digital twins more accessible and meaningful in the UK. It actively enable industries and innovators to safely embrace, explore and realise their dynamic power.
            Find out more UK Digital Twin Centre
    • Case studies
          • Black Founders Programme Showcase event.

            SymphoMe: case study

            Part of the FutureScope's Black Founders Programme, Digital Catapult supported Nyangibo Gallery to get investment ready and receive business expertise
    • Events
    • Blogs
    • Publications
          • Glass globe encircled by verdant forest flora, symbolizing nature, environment, sustainability, ESG, and climate change awareness, generative ai

            Get involved

            Be the first to know about upcoming resources, events and activities in the BridgeAI programme.
            Glass globe encircled by verdant forest flora, symbolizing nature, environment, sustainability, ESG, and climate change awareness, generative ai

            The Programme

            Find out more about how the Innovate UK BridgeAI programme and how it aims to stimulate the adoption AI and...
    • Press releases
  • Search
  • Contact
case-studies

RealVNC: case study

Testing a new way of reducing C++ vulnerabilities through Digital Security by Design

RealVNC uses C++ to build the desktop clients that form part of their VNC Connect secure remote access solution. As part of the Digital Security by Design (DSbD) Technology Access Programme, they have been experimenting with the CHERI Morello board and software.

As a SaaS business using desktop, mobile software, and cloud infrastructure, RealVNC faces a wide range of security issues, including bugs in others’ code and external threats. The C++ codebase has, in the past, faced security issues catalogued by the CVE Program, such as potentially exploitable buffer overflows and elevation of privilege exposure. Increasing cyber security through a change in hardware enables the prevention of memory-related cyber-attacks, which is where around 70% of exploits take place.

Compiling, running, and testing their software on the Morello platform should allow the RealVNC team to spot more obvious logic errors that have the potential to affect security. 

Digital Catapult is running the DSbD Technology Access Programme (TAP), and is supporting RealVNC throughout this project.

The benefits of the Morello Board implementation

The CHERI based Morello evaluation board is a prototype System on Chip (SoC) and development board. Developed by UK-based Arm, the Morello board is a real-world test platform for Arm’s Morello prototype architecture, which is based on the University of Cambridge Computer Lab’s CHERI protection model. It is the first hardware implementation of DSbD technology. 

CHERI extends conventional hardware instruction-set architectures (ISAs) with new architectural features to enable fine-grained memory protection and highly scalable software compartmentalisation. This architecture, when deployed, could do away with whole classes of possible exploits, with a far lower chance of zero-day vulnerabilities being exploited. This would significantly reduce the ability of bad actors to capture user data, take over machines, or shut down critical systems – problems affecting most industries today.

RealVNC-Full-Colour-CMYK

The story so far

RealVNC has ported its core codebase and all desktop applications to run on the Morello device using the CHERI ABI/pure capability mode (as far as possible within the current limitations of the environment). The company has begun performance and security testing: evaluating the pixel throughput of their remote desktop software with the new pure capability mode, and aiming to identify previously undetected programming errors. RealVNC is also evaluating whether CHERI would have effectively detected those legacy bugs catalogued previously by the CVE Program.

As a result of the programme, the company team now understands the CHERI architecture itself – the capabilities encoded into 128-bit pointers – and the implications this has for porting existing software. They also have a better understanding of what can be done in terms of mitigating diverse types of security error, and have learned more about FreeBSD as a platform. 

RealVNC will continue to evaluate the architecture against known security issues, as well as attempting to break their software on the platform to see what can be improved in the codebase. They are also looking at more of the CHERI-specific mechanisms to see where they could be best used within their software.

About Digital Security by Design

Digital Security by Design (DSbD) is a government led initiative to enable hardware and software developers to make their products more robust and resilient to cyber-attacks. Digital Catapult is running the Technology Access Programme on behalf of UKRI to facilitate experimentation and early adoption by UK companies. This includes implementing updated hardware architecture, developing the software and system development tools that will run on it, and demonstrating its application and value within different industry sectors.

Interested in getting involved? Learn more about Digital Security by Design.