TC: Medium: Collaborative Research: Random Number Generation and Use in Virtualized Environments
TC: Medium: Collaborative Research: Random Number Generation and Use in Virtualized Environments
批准号:
1065134
负责人:
Michael Swift
金额:
$74.91万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2011
资助国家:
美国
项目状态:
已结题
起止时间:
2011-09-01 至 2017-08-31
中文摘要
虚拟机管理程序和虚拟化简化了应用程序和系统部署。虚拟化的诸多好处导致人们一头扎进了虚拟化无处不在的世界。但是,虚拟化可以打破应用程序和操作系统对平台的假设。本研究调查了一个重要的情况下:虚拟化和随机数发生器(RNG)的交集。强随机性是当今计算机安全工具的必要条件。在虚拟化设置中部署现有的RNG会引入漏洞。当RNG失败时,灾难性的攻击可能会对现代信息安全所依赖的加密服务进行攻击。虚拟机快照可用于重置虚拟机及其包含的应用程序,可能会导致RNG重复输出并破坏某些加密系统。此外,虚拟化环境可以降低RNG输出的质量,因为熵源是虚拟的,而不是物理硬件,因此降低quality.This研究开发的理论和架构基础,为下一代的RNG设计和RNG使用机制。调查人员使用程序源代码的动态和静态分析来量化VM引入的漏洞的范围。他们开发新的、安全的RNG系统,用于VM。最后,本研究通过扩展可证明安全技术来更好地解释RNG在虚拟化环境中部署和使用的现实,从而推进了密码理论,这项工作不仅通过更强大的RNG系统提供了实际影响,而且还在生成和使用随机性的重要领域开辟了密码理论的新方向。
英文摘要
Hypervisors and virtualization simplify application and system deployment. The many benefits of virtualization have resulted in a headlong rush into a world where virtualization is ubiquitous. However, virtualization can break assumptions that applications and operating systems make about the platform. This research investigates an important case: the intersection of virtualization and random-number generators (RNGs). Strong randomization is requisite in today's computer security tools.Deployment of existing RNGs in virtualized settings introduces vulnerabilities. When RNGs fail, catastrophic attacks can be mounted on the the cryptographic services upon which modern information security relies. VM snapshots, which can be used to reset a VM and its contained applications, can cause RNGs to repeat outputs and break some encryption systems. Moreover, the environment presented by virtualization can degrade the quality of RNG outputs because entropy sources are virtual rather than physical hardware and hence lower quality.This research develops the theoretical and architectural foundations for the next generation of RNG designs and RNG-using mechanisms. The investigators quantify the scope of VM-introduced vulnerabilities using dynamic and static analysis of program source code. They develop new, secure RNG systems for use in VMs. Finally, the reserearch advances cryptographic theory by extending provable security techniques to better account for the realities of RNG deployment and use in virtualized settings.This work not only provides practical impact via stronger RNG systems but also opens up new directions in cryptographic theory in the important areas of generating and using randomness.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: PPoSS: Planning: Scaling Secure Serverless Computing on Heterogeneous Datacenters
-
批准号:2028818
-
项目类别:Standard Grant
-
资助金额:$8.98万
-
财政年份:2020
-
负责人:Michael Swift
-
依托单位:
CNS Core: Medium: Collaborative Research: Persistent memory objects for consistent sharing in Non-Volatile Main Memories
-
批准号:1900758
-
项目类别:Continuing Grant
-
资助金额:$50.97万
-
财政年份:2019
-
负责人:Michael Swift
-
依托单位:
CSR:Small:System Support for Petabyte Memories
-
批准号:1815656
-
项目类别:Standard Grant
-
资助金额:$49.98万
-
财政年份:2018
-
负责人:Michael Swift
-
依托单位:
CSR: Small: Architectural and Operating System Support for Non-volatile Memory
-
批准号:1617824
-
项目类别:Standard Grant
-
资助金额:$49.91万
-
财政年份:2016
-
负责人:Michael Swift
-
依托单位:
Conference Funding Proposal: Advances in Cryptology - CRYPTO 2015
-
批准号:1536054
-
项目类别:Standard Grant
-
资助金额:$1.0万
-
财政年份:2015
-
负责人:Michael Swift
-
依托单位:
CNS Student Travel Support for the 25th ACM Symposium on Operating Systems Principles (SOSP 2013)
-
批准号:1341823
-
项目类别:Standard Grant
-
资助金额:$2.49万
-
财政年份:2013
-
负责人:Michael Swift
-
依托单位:
TWC: Frontier: Collaborative: Rethinking Security in the Era of Cloud Computing
-
批准号:1330308
-
项目类别:Continuing Grant
-
资助金额:$199.51万
-
财政年份:2013
-
负责人:Michael Swift
-
依托单位:
CSR: Medium: WasteNot: Streamlining Virtual Memory for Modern Systems
-
批准号:1302260
-
项目类别:Continuing Grant
-
资助金额:$74.91万
-
财政年份:2013
-
负责人:Michael Swift
-
依托单位:
CSR: Small: Advancing Operating System Interfaces to Solid-State Storage
-
批准号:1218485
-
项目类别:Standard Grant
-
资助金额:$48.71万
-
财政年份:2012
-
负责人:Michael Swift
-
依托单位:
TC: Small: Collaborative Research:Protecting Commodity Operating Systems From Vulnerable Device Drivers
-
批准号:0915363
-
项目类别:Standard Grant
-
资助金额:$24.84万
-
财政年份:2009
-
负责人:Michael Swift
-
依托单位:
CSR-DMSS, SM: Operating System Abstractions for Modern Hardware
-
批准号:0834473
-
项目类别:Continuing Grant
-
资助金额:$41.98万
-
财政年份:2008
-
负责人:Michael Swift
-
依托单位:
CAREER: Improving the Quality and Performance of Device Drivers
-
批准号:0745517
-
项目类别:Standard Grant
-
资助金额:$40.0万
-
财政年份:2008
-
负责人:Michael Swift
-
依托单位:
海外基金