课题基金 / 基金详情

CSR-DMSS, SM: Aeolus: Secure Support for Preserving Confidentiality and Integrity in a Distributed Environment

CSR-DMSS, SM: Aeolus: Secure Support for Preserving Confidentiality and Integrity in a Distributed Environment
CSR-DMSS、SM:Aeolus:在分布式环境中保护机密性和完整性的安全支持
批准号:
0834239
负责人:
Barbara Liskov
金额:
$42.0万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2008
资助国家:
美国
项目状态:
已结题
起止时间:
2008-09-01 至 2012-08-31
关键词:

项目摘要

项目成果

Barbara Liskov的其他基金

相似基金

相关文献

中文摘要
翻译
私人和机密信息,如信用卡号码和医疗记录,越来越多地存储在网上。由于人为错误和恶意攻击,这些信息暴露的情况也越来越多。拟议的研究通过设计和实施一个名为Aeolus的新系统来解决这个问题。Aeolus将使应用程序的构建能够大大降低未经授权发布信息的危险。Aeolus包含了一个新的分布式安全模型和它通过分布式平台的支持。模型简单、层次高;我们的目标是提供一个易于使用和理解的工具,以便在实践中使用。此外,Aeolus允许程序员使用自己选择的编程语言,也可以使用第三方提供的组件。安全模型基于信息流控制,它通过控制对信息的处理来防止机密信息泄露。该模型包含了提供安全和精确授权的新方法。拟议的研究还包括第一个概念验证实现,以允许对模型进行评估,第二个实现旨在提高性能并减少可信库的大小,开发存储服务器的架构和复制技术,以防止泄漏,同时不要求用户加密他们的信息。这项工作解决了在线信息的一个紧迫问题,因为它将大大减少由于错误和恶意攻击而导致的这种暴露。它还将通过教育对社会产生影响,包括参与项目的学生和通过课件的学生。
英文摘要
AbstractPrivate and confidential information, e.g., credit card numbers and medicalrecords, is increasingly being stored online. Also increasingly this information is exposed due to human errors and malicious attacks. The proposed research addresses this problem through the design and implementation of a new system, called Aeolus. Aeolus will enable construction of applications in a way that greatly reduces the danger of unauthorized release of information. Aeolus includes both a new distributed security model and its support via a distributed platform. The model is simple and high level; the goal is to provide a tool that is easy to use and understand, so that it will be used in practice. In addition, Aeolus allows programmers to use programming languages of their choice and also to use components provided by third parties. The security model is based on information flow control, which prevents leaks of confidential information by controlling what can be done with information. The model contains novel ways to provide safe and precise delegation of authority. The proposed research additionally includes a first proof-of-concept implementation to allow evaluation of the model, a second implementation aimed at improving performance and reducing the size of the trusted base, a development of an architecture and replication techniques for storage servers that prevent leaks while not requiring users to encrypt their information. The work addresses a pressing problem with online information since it will greatly reduce this exposure due to errors and malicious attacks. It will additionally impact society through education, both of students on the project and through courseware.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
CSR: Medium: Collaborative Research: Fast and Simple Concurrency Through Data-Abstraction Transactions
ITR: Collaborative Research: (ASE+NHS) - (int): BFT-LS: Byzantine Fault Tolerance for Large-Scale, High-Performance Distributed Storage Systems
Understanding Degrees of Isolation
Support for Data Sharing in a Heterogeneous Distributed System.
海外基金