CAREER: Infrastructure for Secure Cloud Computing
职业:安全云计算基础设施
基本信息
- 批准号:1253870
- 负责人:
- 金额:$ 48.06万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Continuing Grant
- 财政年份:2013
- 资助国家:美国
- 起止时间:2013-06-01 至 2015-10-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Infrastructure-as-a-service (IaaS) cloud computing systems are revolutionizing business, government, and science by providing easy access to scalable computing. These public services, as offered by Amazon, Google, Microsoft, and others, allow an arbitrary customer to rent, by the hour, the resources needed to run their applications within virtual machines (VMs) hosted on the provider?s compute infrastructure. With these new services, however, comes subtle new security issues. Prior work by the PI uncovered attacks that abuse two aspects unique to cloud computing: resource sharing among mutually distrustful customers and pricing that incentivizes malicious behavior. The proposed research is organized along the two themes of resource sharing and pricing. In the first theme, the work explores whether cryptographic side channel attacks and resource-freeing attacks pose serious threats to cloud customers and then develops new placement and CPU scheduling algorithms that realize the security principle of soft isolation: minimization of potentially dangerous cross-user scheduling interactions (e.g., sharing a server or CPU core). Within the second theme, the work explores the implications of fine-grained pricing mechanisms on security. This includes developing pricemarks (mechanisms for accurately determining the true costs of a cloud service), understanding customer-controlled placement gaming that exploits cloud performance heterogeneity, and explores pricing-based security mechanisms that, in conjunction with the aforementioned scheduling mechanisms, will degrade fiscal incentivizes for adversarial behavior. The impact of the proposed work will be deeper understanding of threats in cloud IaaS systems, new security design principles, deployable security technologies, and improvements in security education.
基础设施即服务(IaaS)云计算系统通过提供对可扩展计算的轻松访问,正在给企业、政府和科学带来革命性的变化。亚马逊、谷歌、微软和其他公司提供的这些公共服务允许任意客户按小时租用在提供商S计算基础设施上托管的虚拟机(VM)内运行其应用程序所需的资源。然而,随着这些新服务的推出,也带来了微妙的新安全问题。PI之前的工作发现了滥用云计算特有的两个方面的攻击:相互不信任的客户之间的资源共享和激励恶意行为的定价。拟议的研究围绕资源共享和定价这两个主题展开。在第一个主题中,研究了加密侧通道攻击和资源释放攻击是否对云客户构成严重威胁,然后开发了新的布局和CPU调度算法,实现了软隔离的安全原则:最小化潜在危险的跨用户调度交互(例如,共享服务器或CPU核心)。在第二个主题中,这项工作探索了细粒度定价机制对安全的影响。这包括开发价格标记(用于准确确定云服务的真实成本的机制),了解利用云性能异质性的客户控制的配售游戏,以及探索基于定价的安全机制,与上述调度机制结合使用,将降低对敌对行为的财务激励。拟议工作的影响将是更深入地了解云IaaS系统中的威胁、新的安全设计原则、可部署的安全技术以及安全教育的改进。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Thomas Ristenpart其他文献
The TypTop System: Personalized Typo-Tolerant Password Checking
TypTop 系统:个性化的拼写错误密码检查
- DOI:
- 发表时间:
2017 - 期刊:
- 影响因子:0
- 作者:
Rahul Chatterjee;Joanne Woodage;Yuval Pnueli;A. Chowdhury;Thomas Ristenpart - 通讯作者:
Thomas Ristenpart
The Mix-and-Cut Shuffle: Small-Domain Encryption Secure against N Queries
Mix-and-Cut Shuffle:针对 N 查询的小域加密
- DOI:
10.1007/978-3-642-40041-4_22 - 发表时间:
2013 - 期刊:
- 影响因子:0
- 作者:
Thomas Ristenpart;Scott Yilek - 通讯作者:
Scott Yilek
Multi-instance Security and Its Application to Password-Based Cryptography
多实例安全及其在密码密码学中的应用
- DOI:
- 发表时间:
2012 - 期刊:
- 影响因子:0
- 作者:
M. Bellare;Thomas Ristenpart;Stefano Tessaro - 通讯作者:
Stefano Tessaro
BurnBox: Self-Revocable Encryption in a World Of Compelled Access
BurnBox:强制访问世界中的自我撤销加密
- DOI:
- 发表时间:
2018 - 期刊:
- 影响因子:0
- 作者:
Nirvan Tyagi;M. Mughees;Thomas Ristenpart;Ian Miers - 通讯作者:
Ian Miers
Data Stewardship in Clinical Computer Security: Balancing Benefit and Burden in Participatory Systems
临床计算机安全中的数据管理:平衡参与系统中的利益和负担
- DOI:
10.1145/3637316 - 发表时间:
2024 - 期刊:
- 影响因子:0
- 作者:
Emily Tseng;Rosanna Bellini;Yeuk;Alana Ramjit;Thomas Ristenpart;Nicola Dell - 通讯作者:
Nicola Dell
Thomas Ristenpart的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Thomas Ristenpart', 18)}}的其他基金
Collaborative Research: SaTC: CORE: Large: Privacy-Preserving Abuse Prevention for Encrypted Communications Platforms
协作研究:SaTC:核心:大型:加密通信平台的隐私保护滥用预防
- 批准号:
2120651 - 财政年份:2021
- 资助金额:
$ 48.06万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Mixed Distribution Models for Encrypted Data Stores
协作研究:SaTC:CORE:Medium:加密数据存储的混合分布模型
- 批准号:
2055169 - 财政年份:2021
- 资助金额:
$ 48.06万 - 项目类别:
Standard Grant
CAREER: Infrastructure for Secure Cloud Computing
职业:安全云计算基础设施
- 批准号:
1558500 - 财政年份:2015
- 资助金额:
$ 48.06万 - 项目类别:
Continuing Grant
相似海外基金
CPSEC: A Digital Twin Approach for Autonomous Decision Support to Secure Critical Infrastructure
CPSEC:用于自主决策支持的数字孪生方法,以确保关键基础设施的安全
- 批准号:
10099834 - 财政年份:2023
- 资助金额:
$ 48.06万 - 项目类别:
Collaborative R&D
CICI: UCSS: Secure Containers in High-Performance Computing Infrastructure
CICI:UCSS:高性能计算基础设施中的安全容器
- 批准号:
2319975 - 财政年份:2023
- 资助金额:
$ 48.06万 - 项目类别:
Standard Grant
Towards Smart Cities: Scalable and Robust Design and Dimensioning of Secure Fog-Computing Infrastructure to Support Latency Sensitive and Dynamic IoT Applications
迈向智慧城市:安全雾计算基础设施的可扩展且稳健的设计和尺寸设计,以支持延迟敏感和动态物联网应用
- 批准号:
558695-2021 - 财政年份:2022
- 资助金额:
$ 48.06万 - 项目类别:
Postgraduate Scholarships - Doctoral
Collaborative Research: SaTC: CORE: Medium: Enabling Practically Secure Cellular Infrastructure
协作研究:SaTC:核心:中:实现切实安全的蜂窝基础设施
- 批准号:
2055014 - 财政年份:2022
- 资助金额:
$ 48.06万 - 项目类别:
Standard Grant
Piloting A Secure, Scalable, Infrastructure for AI Dementia Research On Routinely Collected Data
基于常规收集的数据,为人工智能痴呆症研究试点安全、可扩展的基础设施
- 批准号:
MR/X005674/1 - 财政年份:2022
- 资助金额:
$ 48.06万 - 项目类别:
Research Grant
Collaborative Research: SaTC: CORE: Medium: Enabling Practically Secure Cellular Infrastructure
协作研究:SaTC:核心:中:实现切实安全的蜂窝基础设施
- 批准号:
2054911 - 财政年份:2022
- 资助金额:
$ 48.06万 - 项目类别:
Standard Grant
Establishing a common federated infrastructure for secure API-driven multi-party federation on clinico-genomic cohorts
为临床基因组队列的安全 API 驱动的多方联盟建立通用的联盟基础设施
- 批准号:
MC_PC_21026 - 财政年份:2022
- 资助金额:
$ 48.06万 - 项目类别:
Intramural
UK-Australia Centre in a Secure Internet of Energy: Supporting Electric Vehicle Infrastructure at the "Edge" of the Grid
英国-澳大利亚安全能源互联网中心:支持电网“边缘”的电动汽车基础设施
- 批准号:
EP/W003325/1 - 财政年份:2022
- 资助金额:
$ 48.06万 - 项目类别:
Research Grant
OAC Core: MedKnights - Towards Secure and Flexible Medical IoT (IoMT) Infrastructure using Generative Adversarial Networks
OAC 核心:MedKnights - 使用生成对抗网络实现安全灵活的医疗物联网 (IoMT) 基础设施
- 批准号:
2212424 - 财政年份:2022
- 资助金额:
$ 48.06万 - 项目类别:
Standard Grant
CC* Integration-Large: Prototyping a Secure Distributed Storage Infrastructure for Accelerating Big Science
CC* Integration-Large:构建安全分布式存储基础设施原型以加速大科学发展
- 批准号:
2126148 - 财政年份:2021
- 资助金额:
$ 48.06万 - 项目类别:
Standard Grant