课题基金 / 基金详情

Synergy: Collaborative: CPS-Security: End-to-End Security for the Internet of Things

Synergy: Collaborative: CPS-Security: End-to-End Security for the Internet of Things
协同:协作:CPS-安全:物联网的端到端安全
批准号:
1505728
负责人:
Philip Levis
金额:
$60.0万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2015
资助国家:
美国
项目状态:
已结题
起止时间:
2015-09-01 至 2018-08-31

项目摘要

项目成果

Philip Levis的其他基金

相似基金

相关文献

中文摘要
翻译
计算无处不在。贺卡有播放歌曲的处理器。烟花有处理器,可以精确地计算爆炸的时间。计算机安装在发动机中,监控燃烧和性能。它们存在于我们的家中、医院、办公室、烤箱、飞机、火车和汽车中。这些计算机联网后将形成物联网(IoT)。由此产生的应用程序和服务有可能比万维网更具变革性。这对安全的影响是巨大的。如今,互联网威胁会窃取信用卡。明天的互联网威胁将使家庭安全系统瘫痪,洪水泛滥,并扰乱医院。根本问题是,这些应用程序由微小的低功耗设备和云服务器上的软件组成,难以联网,并收集需要强大加密技术的敏感数据,但通常是由不具备这些领域专业知识的开发人员编写的。这项研究的目标是让两个开发者在三个月内构建一个完整的、安全的物联网应用程序。第一个是“分布式模型视图控制器”。开发人员将应用程序编写为模型-视图-控制器系统的分布式管道。模型指定应用程序生成和存储什么数据,而称为转换的新抽象指定数据如何从一个模型移动到另一个模型。第二种是“嵌入式网关云”。一个共同的架构主宰着物联网应用。嵌入式设备通过低功率无线与网关通信。该网关处理数据并与更广泛的互联网中的云系统通信。将分布式模型视图控制器集中在这种占主导地位的体系结构上,充分地约束了问题,使系统安全等问题易于处理。三是“端到端的安全”。数据从嵌入式设备加密出现,并且只能由最终用户应用程序解密。服务器可以对加密数据进行计算,多方可以在不学习输入的情况下协作计算结果。数据处理管道的分析允许系统和运行时断言和验证整个应用程序的安全属性。最后一个原则是“软件定义的硬件”。由于设计新的嵌入式设备硬件是耗时的,开发人员依赖于一般的、夸张的解决方案,而忽略了由此产生的安全影响。数据处理流水线可以被编译成原型硬件设计和支持软件以及测试用例、诊断和调试方法,以供开发者提出新设备。这些原则植根于RAVEL,这是一个软件框架,团队在该框架上进行合作,共同贡献,并将其整合到他们关于网络物理系统的课程和课程中。
英文摘要
Computation is everywhere. Greeting cards have processors that play songs. Fireworks have processors for precisely timing their detonation. Computers are in engines, monitoring combustion and performance. They are in our homes, hospitals, offices, ovens, planes, trains, and automobiles. These computers, when networked, will form the Internet of Things (IoT). The resulting applications and services have the potential to be even more transformative than the World Wide Web. The security implications are enormous. Internet threats today steal credit cards. Internet threats tomorrow will disable home security systems, flood fields, and disrupt hospitals. The root problem is that these applications consist of software on tiny low-power devices and cloud servers, have difficult networking, and collect sensitive data that deserves strong cryptography, but usually written by developers who have expertise in none of these areas. The goal of the research is to make it possible for two developers to build a complete, secure, Internet of Things applications in three months.The research focuses on four important principles. The first is "distributed model view controller." A developer writes an application as a distributed pipeline of model-view-controller systems. A model specifies what data the application generates and stores, while a new abstraction called a transform specifies how data moves from one model to another. The second is "embedded-gateway-cloud." A common architecture dominates Internet of Things applications. Embedded devices communicate with a gateway over low-power wireless. The gateway processes data and communicates with cloud systems in the broader Internet. Focusing distributed model view controller on this dominant architecture constrains the problem sufficiently to make problems, such as system security, tractable. The third is "end-to-end security." Data emerges encrypted from embedded devices and can only be decrypted by end user applications. Servers can compute on encrypted data, and many parties can collaboratively compute results without learning the input. Analysis of the data processing pipeline allows the system and runtime to assert and verify security properties of the whole application. The final principle is "software-defined hardware." Because designing new embedded device hardware is time consuming, developers rely on general, overkill solutions and ignore the resulting security implications. The data processing pipeline can be compiled into a prototype hardware design and supporting software as well as test cases, diagnostics, and a debugging methodology for a developer to bring up the new device. These principles are grounded in Ravel, a software framework that the team collaborates on, jointly contributes to, and integrates into their courses and curricula on cyberphysical systems.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
CPS: Medium: Secure Smart Machining
  • 批准号:
    1931750
  • 项目类别:
    Standard Grant
  • 资助金额:
    $120.0万
  • 财政年份:
    2019
  • 负责人:
    Philip Levis
  • 依托单位:
CSR: Medium: A Computing Cloud for Graphical Simulation
  • 批准号:
    1409847
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $85.45万
  • 财政年份:
    2014
  • 负责人:
    Philip Levis
  • 依托单位:
CAREER: Visibility as a Wireless Sensor Network Design Principle
  • 批准号:
    0846014
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $40.0万
  • 财政年份:
    2009
  • 负责人:
    Philip Levis
  • 依托单位:
Collaborative Research: NeTS-ANET: A Network Architecture for Federated Virtual/Physical Worlds
  • 批准号:
    0831163
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $95.0万
  • 财政年份:
    2008
  • 负责人:
    Philip Levis
  • 依托单位:
海外基金