课题基金 / 基金详情

CSR-DMSS, SM: Aeolus: Secure Support for Preserving Confidentiality and Integrity in a Distributed Environment

CSR-DMSS, SM: Aeolus: Secure Support for Preserving Confidentiality and Integrity in a Distributed Environment
CSR-DMSS、SM:Aeolus:在分布式环境中保护机密性和完整性的安全支持
批准号:
0834239
负责人:
Barbara Liskov
金额:
$42.0万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2008
资助国家:
美国
项目状态:
已结题
起止时间:
2008-09-01 至 2012-08-31
关键词:

项目摘要

项目成果

Barbara Liskov的其他基金

相似基金

相关文献

中文摘要
翻译
私人和机密信息,例如,信用卡号码和医疗记录,越来越多地被存储在网上。由于人为错误和恶意攻击,这些信息也越来越多地暴露出来。拟议的研究通过设计和实施一个新的系统,称为风神解决这个问题。Aeolus将以一种大大降低未经授权发布信息的危险的方式构建应用程序。Aeolus包括一个新的分布式安全模型及其通过分布式平台的支持。该模型是简单和高层次的;目标是提供一个易于使用和理解的工具,以便在实践中使用。此外,Aeolus允许程序员使用他们选择的编程语言,也可以使用第三方提供的组件。该安全模型基于信息流控制,通过控制可以对信息执行的操作来防止机密信息泄露。该模型包含提供安全和精确授权的新颖方法。拟议的研究还包括第一个概念验证实现,以允许评估模型,第二个实现,旨在提高性能和减少可信基础的大小,为存储服务器开发一个架构和复制技术,防止泄漏,同时不需要用户加密他们的信息。这项工作解决了在线信息的一个紧迫问题,因为它将大大减少由于错误和恶意攻击而导致的这种暴露。此外,它还将通过教育对社会产生影响,无论是对项目中的学生还是通过课件。
英文摘要
AbstractPrivate and confidential information, e.g., credit card numbers and medicalrecords, is increasingly being stored online. Also increasingly this information is exposed due to human errors and malicious attacks. The proposed research addresses this problem through the design and implementation of a new system, called Aeolus. Aeolus will enable construction of applications in a way that greatly reduces the danger of unauthorized release of information. Aeolus includes both a new distributed security model and its support via a distributed platform. The model is simple and high level; the goal is to provide a tool that is easy to use and understand, so that it will be used in practice. In addition, Aeolus allows programmers to use programming languages of their choice and also to use components provided by third parties. The security model is based on information flow control, which prevents leaks of confidential information by controlling what can be done with information. The model contains novel ways to provide safe and precise delegation of authority. The proposed research additionally includes a first proof-of-concept implementation to allow evaluation of the model, a second implementation aimed at improving performance and reducing the size of the trusted base, a development of an architecture and replication techniques for storage servers that prevent leaks while not requiring users to encrypt their information. The work addresses a pressing problem with online information since it will greatly reduce this exposure due to errors and malicious attacks. It will additionally impact society through education, both of students on the project and through courseware.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
CSR: Medium: Collaborative Research: Fast and Simple Concurrency Through Data-Abstraction Transactions
ITR: Collaborative Research: (ASE+NHS) - (int): BFT-LS: Byzantine Fault Tolerance for Large-Scale, High-Performance Distributed Storage Systems
Understanding Degrees of Isolation
Support for Data Sharing in a Heterogeneous Distributed System.
海外基金