ITR: New Directions in Software Security
ITR: New Directions in Software Security
批准号:
0456717
负责人:
Amit Sahai
金额:
$0.0万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2004
资助国家:
美国
项目状态:
已结题
起止时间:
2004-09-01 至 2008-07-31
中文摘要
摘要:提案(CCR-ITR 0312809) ITR:软件安全的新方向(New Directions in Software security)阿米特·萨海(amit sahaii)普遍认为,当今计算机安全的最大威胁不是加密的弱点,而是有缺陷的软件设计和实现,以及软件和硬件内部信息保护的薄弱。本研究提出开发软件安全领域-通过全自动软件和硬件转换来保护功能对象免受漏洞的侵害。本研究中提出的方法试图为这一领域建立一个新颖而理论上健全的基础。首先,本研究考虑了软件转换的广泛领域,以抵消软件中由缺陷(“bug”)引起的安全漏洞。特别是,该项目将开发理论基础和工具,以防止利用漏洞获得远程系统控制的攻击。更一般地说,本研究旨在对计算受限的软件转换所能提供的安全性进行分类。其次,本研究考虑了软件和硬件隐私问题——如何确保对手无法通过检查软件或硬件来了解重要的秘密。在这种情况下,本研究将研究这样的转换,当攻击者获得对转换后的软件或硬件的访问权限时,它无法了解嵌入在原始软件或硬件中的特定秘密,例如加密密钥或潜在的秘密算法技术。本研究将在各种假设下提出硬件和软件的这种转换,并试图确定何时这种保护是不可能的。
英文摘要
ABSTRACT:Proposal CCR-ITR 0312809 ITR: New Directions in Software SecurityAmit SahaiIt is widely believed that the greatest threat to computer security today is not cryptographic weakness but rather flawed software design and implementation, and weakness in protecting information within software and hardware. This research proposes to develop the area of software security - protecting functional objects from vulnerabilities by means of fully automated software and hardware transformations. The approaches proposed in this research attempt to build a novel and theoretically sound foundation to this field.First, this research considers the broad area of software transformations to counteract security vulnerabilities caused by flaws ("bugs") in software. In particular, this project will develop theoretical foundations and tools for preventing attacks which exploit flaws to gain control of remote systems. More generally, this research will aim to classify the security that computationally limited software transformations can provide.Second, this research considers the question of software and hardware privacy -- how to ensure that an adversary cannot learn important secrets by examining software or hardware. In this case, this research will study transformations such that, when the attacker gains access to the transformed software or hardware, it cannot learn specific secrets embedded in the original software or hardware, such as cryptographic keys or potentially even secret algorithmic techniques. This research will propose such transformations for hardware and software under various assumptions, and seek to determine when such protection is impossible.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
TWC: Frontier: Collaborative: CORe: Center for Encrypted Functionalities
-
批准号:1413955
-
项目类别:Continuing Grant
-
资助金额:$125.01万
-
财政年份:2014
-
负责人:Amit Sahai
-
依托单位:
TWC: Medium: Collaborative Research: Transformative New Approaches to Efficient Secure Computation
-
批准号:1228984
-
项目类别:Standard Grant
-
资助金额:$60.0万
-
财政年份:2012
-
负责人:Amit Sahai
-
依托单位:
TC: Small: New Directions in Encryption
-
批准号:1118096
-
项目类别:Standard Grant
-
资助金额:$49.54万
-
财政年份:2011
-
负责人:Amit Sahai
-
依托单位:
AF: Small: A Theory of Cryptography and the Physical World
-
批准号:0916574
-
项目类别:Standard Grant
-
资助金额:$40.0万
-
财政年份:2009
-
负责人:Amit Sahai
-
依托单位:
CT-ISG: New Directions in Cryptographic Proof Systems
-
批准号:0627781
-
项目类别:Continuing Grant
-
资助金额:$35.0万
-
财政年份:2006
-
负责人:Amit Sahai
-
依托单位:
ITR: New Directions in Software Security
-
批准号:0312809
-
项目类别:Continuing Grant
-
资助金额:$40.0万
-
财政年份:2003
-
负责人:Amit Sahai
-
依托单位:
海外基金