课题基金 / 基金详情

TC: Medium: Collaborative Research: Random Number Generation and Use in Virtualized Environments

TC: Medium: Collaborative Research: Random Number Generation and Use in Virtualized Environments
TC:媒介:协作研究:虚拟化环境中的随机数生成和使用
批准号:
1065134
负责人:
Michael Swift
金额:
$74.91万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2011
资助国家:
美国
项目状态:
已结题
起止时间:
2011-09-01 至 2017-08-31

项目摘要

项目成果

Michael Swift的其他基金

相似基金

相关文献

中文摘要
翻译
管理程序和虚拟化简化了应用程序和系统的部署。虚拟化的诸多好处导致了虚拟化无处不在的趋势。然而,虚拟化可以打破应用程序和操作系统对平台的假设。本研究调查了一个重要的案例:虚拟化和随机数生成器(rng)的交集。在当今的计算机安全工具中,强随机化是必不可少的。在虚拟化环境中部署现有的rng会引入漏洞。当rng失效时,会对现代信息安全所依赖的加密服务造成灾难性的攻击。虚拟机快照可用于重置虚拟机及其包含的应用程序,但可能导致rng重复输出并破坏某些加密系统。此外,虚拟化所呈现的环境可能会降低RNG输出的质量,因为熵源是虚拟的,而不是物理硬件,因此质量较低。本研究为下一代RNG设计和RNG使用机制奠定了理论和架构基础。研究人员通过对程序源代码的动态和静态分析,量化了虚拟机引入的漏洞的范围。他们为虚拟机开发新的、安全的RNG系统。最后,该研究通过扩展可证明的安全技术来推进密码学理论,以更好地解释虚拟环境中RNG部署和使用的现实。这项工作不仅通过更强大的RNG系统提供了实际影响,而且在生成和使用随机性的重要领域开辟了密码学理论的新方向。
英文摘要
Hypervisors and virtualization simplify application and system deployment. The many benefits of virtualization have resulted in a headlong rush into a world where virtualization is ubiquitous. However, virtualization can break assumptions that applications and operating systems make about the platform. This research investigates an important case: the intersection of virtualization and random-number generators (RNGs). Strong randomization is requisite in today's computer security tools.Deployment of existing RNGs in virtualized settings introduces vulnerabilities. When RNGs fail, catastrophic attacks can be mounted on the the cryptographic services upon which modern information security relies. VM snapshots, which can be used to reset a VM and its contained applications, can cause RNGs to repeat outputs and break some encryption systems. Moreover, the environment presented by virtualization can degrade the quality of RNG outputs because entropy sources are virtual rather than physical hardware and hence lower quality.This research develops the theoretical and architectural foundations for the next generation of RNG designs and RNG-using mechanisms. The investigators quantify the scope of VM-introduced vulnerabilities using dynamic and static analysis of program source code. They develop new, secure RNG systems for use in VMs. Finally, the reserearch advances cryptographic theory by extending provable security techniques to better account for the realities of RNG deployment and use in virtualized settings.This work not only provides practical impact via stronger RNG systems but also opens up new directions in cryptographic theory in the important areas of generating and using randomness.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: PPoSS: Planning: Scaling Secure Serverless Computing on Heterogeneous Datacenters
  • 批准号:
    2028818
  • 项目类别:
    Standard Grant
  • 资助金额:
    $8.98万
  • 财政年份:
    2020
  • 负责人:
    Michael Swift
  • 依托单位:
CNS Core: Medium: Collaborative Research: Persistent memory objects for consistent sharing in Non-Volatile Main Memories
  • 批准号:
    1900758
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $50.97万
  • 财政年份:
    2019
  • 负责人:
    Michael Swift
  • 依托单位:
CSR:Small:System Support for Petabyte Memories
  • 批准号:
    1815656
  • 项目类别:
    Standard Grant
  • 资助金额:
    $49.98万
  • 财政年份:
    2018
  • 负责人:
    Michael Swift
  • 依托单位:
CSR: Small: Architectural and Operating System Support for Non-volatile Memory
  • 批准号:
    1617824
  • 项目类别:
    Standard Grant
  • 资助金额:
    $49.91万
  • 财政年份:
    2016
  • 负责人:
    Michael Swift
  • 依托单位:
海外基金