课题基金 / 基金详情

TTP: Medium: A Campus Pilot For A Privacy-Enabled Cloud Storage, Search, and Collaboration Portal for Education

TTP: Medium: A Campus Pilot For A Privacy-Enabled Cloud Storage, Search, and Collaboration Portal for Education
TTP:Medium:支持隐私的云存储、搜索和协作教育门户的校园试点
批准号:
1562376
负责人:
Radu Sion
金额:
$99.98万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2016
资助国家:
美国
项目状态:
已结题
起止时间:
2016-09-01 至 2019-08-31

项目摘要

项目成果

Radu Sion的其他基金

相似基金

相关文献

中文摘要
翻译
随着高等教育机构考虑将服务转移到云端以节省成本和改善协作,成功的大规模采用仍然存在重大挑战。机构不愿冒险部署云,因为到目前为止还缺乏可证明的技术防御。在机构不知情的情况下,放弃了对敏感数据的控制,责任被转移,数据泄露风险显著增加。此外,对监管敏感的数据已成为一个越来越有吸引力的目标。最近的历史显示,每隔几周就会发生一起重大入侵事件,频率惊人地增加。该项目直接解决了这一重大挑战,通过教育园区试点过渡到实践-可搜索的云存储和协作工具,具有完全的云内隐私、运行时安全性,并且不会转移教育人员和学生的责任。试点为24,500名学生和2,500名教育工作者提供安全的云存储。通过研究人员和学生参与其操作,它构成了在真实环境中部署安全协议的试验台。为学术研究目的广泛传播数据是试点工作的一个组成部分。收集的数据点不仅在安全社区中,而且在存储和云研究社区中,都是重要的知识存储库。该项目将创造大量与信任和安全有关的信息技术工作岗位,这些工作岗位必须留在美国境内,以维持美国的经济和政治安全。该项目培训学生,并为培养一支熟练的网络安全国内劳动力做出贡献,以满足我们国家的需求。该项目提供了新的课程材料,涉及代表性不足的群体,包括至少一名女性博士生。该工作的技术基础依赖于新的机制,确保在离开受信任的客户端之前对数据进行高度加密,同时允许用户仍然安全地协作、查询、共享、同步、搜索、备份等。与传统智慧相反,该项目构建了一个也确实实用的安全设计,但如果使用以服务器为中心的方法,则不可行,在该方法中,搜索操作在服务器端对加密数据执行,计算成本很高,而且表达能力必然受到限制。相反,试点基于一种高效的设计,其中操作以可扩展、高效的方式分发到客户端逻辑,操作速度比加密数据上的同等服务器代码快数量级。为了进一步优化处理,该系统使客户能够通过云中介的渠道和机制,以分布式安全的方式利用彼此的工作(如索引)。总体而言,该系统确保了云永远无法访问用户数据或查看用户搜索查询。最终,客户将获得所有云优势,同时确保全面合规。即使云提供商被攻破,数据也会得到充分保护。
英文摘要
As higher education institutions consider moving services to the cloud to save costs and improve collaboration, significant challenges to successful large-scale adoption still exist. Institutions are unwilling to risk cloud deployment because provable technological defenses have thus far been lacking. Control over sensitive data is relinquished without the institution's knowledge, liability is shifted and data breach risks are significantly increased. Further, regulatory-sensitive data has become an increasingly attractive target. Recent history shows one major breach every few weeks, with an alarming increase in frequency. This project directly addresses this significant challenge by transitioning to practice -- through an educational campus pilot -- searchable cloud storage and collaboration tools with full in-cloud privacy, at-runtime security and no shift in liability for educators and students. The pilot provides secure cloud storage to 24,500 students and 2,500 educators. It constitutes a testbed for deploying secure protocols in a live environment via the participation of researchers and students in its operation. Extensive data dissemination for academic research purposes is an integral part of the pilot. Collected data points serve as significant knowledge repositories not only in the security community but also in the storage and cloud research communities. The project will result in the creation of a significant number of trust and security-related information technology jobs which must remain stateside to maintain the economic and political security of the United States. The project trains students and contributes to the creation of a skilled cyber-security domestic workforce available to fulfill our nation's needs. The project provides new course material and involves underrepresented groups, including at least one female PhD student.The technical underpinnings of the work rely on new mechanisms that ensure data is strongly encrypted before leaving trusted client premises while allowing users to still securely collaborate, query, share, synchronize, search, backup etc. Contrary to conventional wisdom, the project constructs a secure design that is also truly practical, but would not have been feasible with a server-centric approach in which search operations are performed server-side on encrypted data and are computationally expensive and necessarily limited in expressiveness. Instead, the pilot is based on an efficient design in which operations are distributed to client-side logic in a scalable, efficient manner, operating orders of magnitude faster than the equivalent server code on encrypted data. To further optimize processing, the system enables clients to leverage each other's work (such as indexing) in a distributed secure manner, through cloud-mediated conduits and mechanisms. Overall, the system ensures the cloud cannot ever access user data or see user search queries. Ultimately, clients receive all cloud benefits while ensuring full regulatory compliance. Even if the cloud provider is breached, data is fully protected.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SaTC: CORE: Small: Efficient Plausible Deniability Systems
  • 批准号:
    2052951
  • 项目类别:
    Standard Grant
  • 资助金额:
    $49.97万
  • 财政年份:
    2021
  • 负责人:
    Radu Sion
  • 依托单位:
NSFSaTC-BSF: TWC: Small: Practical Plausibly Deniable Encryption through Low-Level Storage Device Behavior
  • 批准号:
    1526707
  • 项目类别:
    Standard Grant
  • 资助金额:
    $50.0万
  • 财政年份:
    2015
  • 负责人:
    Radu Sion
  • 依托单位:
CSR: Small: Collaborative Research: Sensorprint: Hardware-Enforced Information Authentication for Mobile Systems
  • 批准号:
    1526102
  • 项目类别:
    Standard Grant
  • 资助金额:
    $25.0万
  • 财政年份:
    2015
  • 负责人:
    Radu Sion
  • 依托单位:
CSR: Small: Collaborative Research: Enabling Cost-Effective Cloud HPC
  • 批准号:
    1318572
  • 项目类别:
    Standard Grant
  • 资助金额:
    $15.0万
  • 财政年份:
    2013
  • 负责人:
    Radu Sion
  • 依托单位:
海外基金