CICI: Secure Data Architecture: Ensuring Data Integrity at the Beginning of the Scientific Workflow; A Mini-ScienceDMZ for Instruments
CICI: Secure Data Architecture: Ensuring Data Integrity at the Beginning of the Scientific Workflow; A Mini-ScienceDMZ for Instruments
批准号:
1547099
负责人:
Steven Wallace
金额:
$48.85万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2016
资助国家:
美国
项目状态:
已结题
起止时间:
2016-01-01 至 2018-12-31
中文摘要
现代科学仪器,如望远镜、电子显微镜和DNA测序仪,利用机载计算机捕获和处理数据。这些车载计算机将仪器“看到”的内容转换为数字数据。就望远镜而言,机载计算机将镜头聚焦后的图像转换成数字jpeg文件。像大多数计算机一样,这些仪器容易受到基于网络的攻击,这可能会损害数据并损坏仪器。当一台仪器因网络攻击而受损时,它所支持的科学研究就会陷入停顿。为了确保研究人员能够保持对仪器和数据的控制和完整性,该项目开发了一种与仪器的机载计算机一起工作的设备,以防止未经授权的访问和数据操纵。该装置既可作为仪器的防火墙,又可作为数据传输系统,确保仪器收集的数据不被更改。通过该项目开发的技术将有更广泛的应用,如保护医疗设备、工业机器和飞机。该项目设计、开发并测试一个小型设备的部署,该设备的功能包括防火墙、大型文件传输设施和网络性能监视器。该设备由一个小的、低功率的盒子组成,位于仪器和校园网之间。防火墙策略可由研究人员(或其指定人员)通过基于云的门户进行配置。文件传输设施可以远距离传输大型数据文件,同时保持可靠的性能。该设施还将对文件进行数字签名,因此可以在整个科学工作流程中验证数据完整性。反过来,网络性能监视器将与相关的在线系统连接,因此可以很容易地识别性能瓶颈。最终,这种架构和实现将确保最佳的数据处理,同时在整个科学工作流程中保护仪器及其数据的完整性。
英文摘要
Modern scientific instruments such as telescopes, electron microscopes, and DNA sequencers, capture and process data using on-board computers. These on-board computers transform what the instrument "sees" into digital data. In the case of a telescope, the onboard computer converts the lens' focused image into a digital jpeg file. Like most computers, these instruments are vulnerable to network-based attacks, which risk compromising data and harming the instrument. When an instrument is compromised via a network attack, the science it supports grinds to a halt. To ensure that researchers can maintain the control and integrity of their instruments and data, this project develops a device that works with the instruments' on-board computers to prevent unauthorized access and manipulation of data. The device serves as both a firewall for the instrument and as a data transfer system that ensures data collected by instrument is not altered. Technology developed through this project will have broader applications like protecting medical devices, industrial machines, and aircraft.The project designs, develops, and tests the deployment of a small device that functions as a firewall, large file transfer facility, and network performance monitor. The device consists of a small, low-power box positioned between the instrument and the campus network. Firewall policies are configurable by the researcher (or their designate) via a cloud-based portal. The file transfer facility will transfer large data files over long distances, while maintaining reliable performance. This facility will also digitally sign files, so data integrity can be verified throughout the science workflow. In turn, the network performance monitor will interface with associated online systems, so performance bottlenecks can be easily identified. Ultimately, this architecture and implementation will ensure optimal data processing while safeguarding the integrity of the instrument and its data throughout the scientific workflow.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
EAGER: Network Training Internship Program: Collaborative Research
-
批准号:1140638
-
项目类别:Standard Grant
-
资助金额:$27.06万
-
财政年份:2011
-
负责人:Steven Wallace
-
依托单位:
Systematic Sampling of the Gray Fossil Site Vertebrates: A Unique Mio-Pliocene Fauna from the Southern Appalachians
-
批准号:0958985
-
项目类别:Continuing Grant
-
资助金额:$32.43万
-
财政年份:2010
-
负责人:Steven Wallace
-
依托单位:
Workshop: Security at Line Speed: Developing Next Generation Guidelines for Network Security in the Research and Higher Education Community
-
批准号:0310414
-
项目类别:Standard Grant
-
资助金额:$7.47万
-
财政年份:2003
-
负责人:Steven Wallace
-
依托单位:
Network Management Tools for End-to-end Performance Measurement
-
批准号:0129592
-
项目类别:Standard Grant
-
资助金额:$69.94万
-
财政年份:2002
-
负责人:Steven Wallace
-
依托单位:
海外基金