TC: Medium: Collaborative Research: Random Number Generation and Use in Virtualized Environments
TC:媒介:协作研究:虚拟化环境中的随机数生成和使用
基本信息
- 批准号:1065288
- 负责人:
- 金额:$ 44.99万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2011
- 资助国家:美国
- 起止时间:2011-09-01 至 2016-08-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Hypervisors and virtualization simplify application and system deployment. The many benefits of virtualization have resulted in a headlong rush into a world where virtualization is ubiquitous. However, virtualization can break assumptions that applications and operating systems make about the platform. This research investigates an important case: the intersection of virtualization and random-number generators (RNGs). Strong randomization is requisite in today's computer security tools.Deployment of existing RNGs in virtualized settings introduces vulnerabilities. When RNGs fail, catastrophic attacks can be mounted on the the cryptographic services upon which modern information security relies. VM snapshots, which can be used to reset a VM and its contained applications, can cause RNGs to repeat outputs and break some encryption systems. Moreover, the environment presented by virtualization can degrade the quality of RNG outputs because entropy sources are virtual rather than physical hardware and hence lower quality.This research develops the theoretical and architectural foundations for the next generation of RNG designs and RNG-using mechanisms. The investigators quantify the scope of VM-introduced vulnerabilities using dynamic and static analysis of program source code. They develop new, secure RNG systems for use in VMs. Finally, the reserearch advances cryptographic theory by extending provable security techniques to better account for the realities of RNG deployment and use in virtualized settings.This work not only provides practical impact via stronger RNG systems but also opens up new directions in cryptographic theory in the important areas of generating and using randomness.
虚拟机管理程序和虚拟化简化了应用程序和系统部署。虚拟化的诸多好处导致人们一头扎进了虚拟化无处不在的世界。但是,虚拟化可以打破应用程序和操作系统对平台的假设。本研究调查了一个重要的情况下:虚拟化和随机数发生器(RNG)的交集。强随机性是当今计算机安全工具的必要条件。在虚拟化设置中部署现有的RNG会引入漏洞。当RNG失败时,灾难性的攻击可能会对现代信息安全所依赖的加密服务进行攻击。虚拟机快照可用于重置虚拟机及其包含的应用程序,可能会导致RNG重复输出并破坏某些加密系统。此外,虚拟化环境可以降低RNG输出的质量,因为熵源是虚拟的,而不是物理硬件,因此降低quality.This研究开发的理论和架构基础,为下一代的RNG设计和RNG使用机制。调查人员使用程序源代码的动态和静态分析来量化VM引入的漏洞的范围。他们开发新的、安全的RNG系统,用于VM。最后,本研究通过扩展可证明安全技术来更好地解释RNG在虚拟化环境中部署和使用的现实,从而推进了密码理论,这项工作不仅通过更强大的RNG系统提供了实际影响,而且还在生成和使用随机性的重要领域开辟了密码理论的新方向。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Yevgeniy Dodis其他文献
Signcryption
- DOI:
10.1007/0-387-23483-7_398 - 发表时间:
2005 - 期刊:
- 影响因子:0
- 作者:
Yevgeniy Dodis - 通讯作者:
Yevgeniy Dodis
Leftover Hash Lemma, Revisited
- DOI:
- 发表时间:
2011 - 期刊:
- 影响因子:
- 作者:
Boaz Barak;Yevgeniy Dodis;Hugo Krawczyk;Olivier Pereira;Krzysztof Pietrzak;Francois-Xavier Standaert;Yu Yu; - 通讯作者:
Yevgeniy Dodis的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Yevgeniy Dodis', 18)}}的其他基金
Collaborative Research: SaTC: CORE: Medium: Making Crypto Too BIG To Break
合作研究:SaTC:核心:媒介:让加密货币变得太大而无法破坏
- 批准号:
2055578 - 财政年份:2021
- 资助金额:
$ 44.99万 - 项目类别:
Standard Grant
SaTC: CORE: Small: On the Power of Preprocessing and Non-Uniformity
SaTC:核心:小:论预处理和非均匀性的力量
- 批准号:
1815546 - 财政年份:2018
- 资助金额:
$ 44.99万 - 项目类别:
Standard Grant
TWC: Small: On the Design of Secure Hash Functions and Block Ciphers
TWC:小:关于安全散列函数和分组密码的设计
- 批准号:
1619158 - 财政年份:2016
- 资助金额:
$ 44.99万 - 项目类别:
Standard Grant
TWC: Small: On Imperfect Randomness and Leakage-Resilient Cryptography
TWC:小:关于不完美随机性和抗泄漏密码学
- 批准号:
1319051 - 财政年份:2013
- 资助金额:
$ 44.99万 - 项目类别:
Standard Grant
TWC: Medium: Collaborative: The Theory and Practice of Key Derivation
TWC:媒介:协作:密钥派生的理论与实践
- 批准号:
1314568 - 财政年份:2013
- 资助金额:
$ 44.99万 - 项目类别:
Standard Grant
TC: Small: The Design of Secure Hash Functions and Block Ciphers
TC:小:安全散列函数和分组密码的设计
- 批准号:
1017471 - 财政年份:2010
- 资助金额:
$ 44.99万 - 项目类别:
Standard Grant
CT-ISG: On Imperfect Randomness and Exposure-Resilient Cryptography
CT-ISG:关于不完美随机性和暴露弹性密码学
- 批准号:
0831299 - 财政年份:2008
- 资助金额:
$ 44.99万 - 项目类别:
Standard Grant
Collaborative Research: Rigorous Cryptography from Biometrics and Other Noisy Data
合作研究:来自生物识别和其他噪音数据的严格密码学
- 批准号:
0515121 - 财政年份:2005
- 资助金额:
$ 44.99万 - 项目类别:
Standard Grant
Collaborative Research: Mitigating the Damaging Effects of Key Exposure
合作研究:减轻关键暴露的破坏性影响
- 批准号:
0311095 - 财政年份:2003
- 资助金额:
$ 44.99万 - 项目类别:
Continuing Grant
CAREER: Exposure-Resilient Cryptography
职业:暴露弹性密码学
- 批准号:
0133806 - 财政年份:2002
- 资助金额:
$ 44.99万 - 项目类别:
Continuing Grant
相似海外基金
TC: Medium: Collaborative Research: Program Analysis for Smartphone Application Security
TC:媒介:协作研究:智能手机应用程序安全的程序分析
- 批准号:
1630037 - 财政年份:2015
- 资助金额:
$ 44.99万 - 项目类别:
Standard Grant
TC: Medium: Collaborative Research: Program Analysis for Smartphone Application Security
TC:媒介:协作研究:智能手机应用程序安全的程序分析
- 批准号:
1064646 - 财政年份:2011
- 资助金额:
$ 44.99万 - 项目类别:
Standard Grant
TC: Medium: Collaborative Research: Building Trustworthy Applications for Mobile Devices
TC:媒介:协作研究:为移动设备构建值得信赖的应用程序
- 批准号:
1064944 - 财政年份:2011
- 资助金额:
$ 44.99万 - 项目类别:
Standard Grant
TC: Medium: Collaborative Research: Securing Web Advertisements: Fixing the Short-term Crisis and Addressing Long-term Challenges
TC:媒介:协作研究:保护网络广告:解决短期危机并应对长期挑战
- 批准号:
1065216 - 财政年份:2011
- 资助金额:
$ 44.99万 - 项目类别:
Standard Grant
TC: Medium: Collaborative Research: Tracking Adversarial Behavior in Distributed Systems with Secure Networked Provenance
TC:中:协作研究:通过安全网络来源跟踪分布式系统中的对抗行为
- 批准号:
1065130 - 财政年份:2011
- 资助金额:
$ 44.99万 - 项目类别:
Standard Grant
TC: Medium: Collaborative Research: Securing Web Advertisements: Fixing the Short-term Crisis and Addressing Long-term Challenges
TC:媒介:协作研究:保护网络广告:解决短期危机并应对长期挑战
- 批准号:
1065537 - 财政年份:2011
- 资助金额:
$ 44.99万 - 项目类别:
Standard Grant
TC: Medium: Collaborative Research: Program Analysis for Smartphone Application Security
TC:媒介:协作研究:智能手机应用程序安全的程序分析
- 批准号:
1064844 - 财政年份:2011
- 资助金额:
$ 44.99万 - 项目类别:
Standard Grant
TC: Medium: Collaborative Research: Tracking Adversarial Behavior in Distributed Systems with Secure Networked Provenance
TC:中:协作研究:通过安全网络来源跟踪分布式系统中的对抗行为
- 批准号:
1064986 - 财政年份:2011
- 资助金额:
$ 44.99万 - 项目类别:
Standard Grant
TC: Medium: Collaborative Research: Building Trustworthy Applications for Mobile Devices
TC:媒介:协作研究:为移动设备构建值得信赖的应用程序
- 批准号:
1064900 - 财政年份:2011
- 资助金额:
$ 44.99万 - 项目类别:
Standard Grant
TC: Medium: Collaborative Research: Program Analysis for Smartphone Application Security
TC:媒介:协作研究:智能手机应用程序安全的程序分析
- 批准号:
1064997 - 财政年份:2011
- 资助金额:
$ 44.99万 - 项目类别:
Standard Grant