课题基金 / 基金详情

ITR: New Directions in Software Security

ITR: New Directions in Software Security
ITR:软件安全的新方向
批准号:
0456717
负责人:
Amit Sahai
金额:
$0.0万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2004
资助国家:
美国
项目状态:
已结题
起止时间:
2004-09-01 至 2008-07-31

项目摘要

项目成果

Amit Sahai的其他基金

相似基金

相关文献

中文摘要
翻译
摘要:提案CCR-ITR 0312809 ITR:软件安全的新方向Amit Sahai人们普遍认为,当今计算机安全面临的最大威胁不是加密弱点,而是软件设计和实现的缺陷,以及在保护软件和硬件内的信息方面的弱点。这项研究建议发展软件安全领域-通过全自动的软件和硬件转换来保护功能对象免受漏洞的攻击。这项研究提出的方法试图为这一领域建立一个新颖的和理论上可靠的基础。首先,本研究考虑了软件转换的广泛领域,以抵消由软件中的缺陷(错误)引起的安全漏洞。特别是,该项目将开发用于防止利用缺陷控制远程系统的攻击的理论基础和工具。第二,本研究考虑了软件和硬件隐私的问题--如何确保对手不能通过检查软件或硬件来获取重要秘密。在这种情况下,这项研究将研究转换,以便当攻击者获得对转换后的软件或硬件的访问权限时,它无法了解嵌入原始软件或硬件中的特定秘密,例如密钥,甚至可能是秘密算法技术。这项研究将在各种假设下为硬件和软件提出这样的转换,并试图确定何时不可能进行这样的保护。
英文摘要
ABSTRACT:Proposal CCR-ITR 0312809 ITR: New Directions in Software SecurityAmit SahaiIt is widely believed that the greatest threat to computer security today is not cryptographic weakness but rather flawed software design and implementation, and weakness in protecting information within software and hardware. This research proposes to develop the area of software security - protecting functional objects from vulnerabilities by means of fully automated software and hardware transformations. The approaches proposed in this research attempt to build a novel and theoretically sound foundation to this field.First, this research considers the broad area of software transformations to counteract security vulnerabilities caused by flaws ("bugs") in software. In particular, this project will develop theoretical foundations and tools for preventing attacks which exploit flaws to gain control of remote systems. More generally, this research will aim to classify the security that computationally limited software transformations can provide.Second, this research considers the question of software and hardware privacy -- how to ensure that an adversary cannot learn important secrets by examining software or hardware. In this case, this research will study transformations such that, when the attacker gains access to the transformed software or hardware, it cannot learn specific secrets embedded in the original software or hardware, such as cryptographic keys or potentially even secret algorithmic techniques. This research will propose such transformations for hardware and software under various assumptions, and seek to determine when such protection is impossible.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
TWC: Frontier: Collaborative: CORe: Center for Encrypted Functionalities
  • 批准号:
    1413955
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $125.01万
  • 财政年份:
    2014
  • 负责人:
    Amit Sahai
  • 依托单位:
TWC: Medium: Collaborative Research: Transformative New Approaches to Efficient Secure Computation
TC: Small: New Directions in Encryption
AF: Small: A Theory of Cryptography and the Physical World
海外基金