课题基金 / 基金详情

TTP: Medium: A Campus Pilot For A Privacy-Enabled Cloud Storage, Search, and Collaboration Portal for Education

TTP: Medium: A Campus Pilot For A Privacy-Enabled Cloud Storage, Search, and Collaboration Portal for Education
TTP:Medium:支持隐私的云存储、搜索和协作教育门户的校园试点
批准号:
1562376
负责人:
Radu Sion
金额:
$99.98万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2016
资助国家:
美国
项目状态:
已结题
起止时间:
2016-09-01 至 2019-08-31

项目摘要

项目成果

Radu Sion的其他基金

相似基金

相关文献

中文摘要
翻译
随着高等教育机构考虑将服务转移到云端以节省成本并改善协作,成功大规模采用的重大挑战仍然存在。机构不愿意冒险部署云,因为迄今为止还缺乏可证明的技术防御。在机构不知情的情况下,对敏感数据的控制被放弃,责任被转移,数据泄露风险显著增加。此外,监管敏感数据已成为越来越有吸引力的目标。最近的历史表明,每隔几周就会发生一次重大入侵,而且频率惊人地增加。该项目直接解决了这一重大挑战,通过一个教育校园试点,将可搜索的云存储和协作工具过渡到实践中,具有完整的云内隐私、运行时安全性,并且不会转移教育工作者和学生的责任。该试点项目为24,500名学生和2,500名教育工作者提供安全的云存储。它构成了一个测试平台,通过研究人员和学生参与其操作,在实时环境中部署安全协议。以学术研究为目的的广泛数据传播是该试点的一个组成部分。收集的数据点不仅在安全社区,而且在存储和云研究社区中都是重要的知识库。该项目将创造大量与信任和安全相关的信息技术工作,这些工作必须留在美国本土,以维持美国的经济和政治安全。该项目培训学生,并有助于建立一支熟练的网络安全国内劳动力队伍,以满足我们国家的需求。该项目提供了新的课程材料,并涉及了代表性不足的群体,包括至少一名女博士生。这项工作的技术基础依赖于确保数据在离开受信任的客户端之前进行强加密的新机制,同时允许用户仍然安全地协作、查询、共享、同步、搜索、备份等。与传统观点相反,该项目构建了一个真正实用的安全设计,但对于以服务器为中心的方法来说是不可行的,在这种方法中,搜索操作是在服务器端对加密数据执行的,并且计算成本很高,而且必然在表达性方面受到限制。相反,该试点基于一种高效的设计,其中操作以可伸缩、高效的方式分发到客户端逻辑,操作速度比加密数据上的等效服务器代码快几个数量级。为了进一步优化处理,该系统使客户端能够通过云中介的管道和机制以分布式安全的方式利用彼此的工作(例如索引)。总的来说,该系统确保云永远不会访问用户数据或查看用户搜索查询。最终,客户在确保完全遵守法规的同时获得所有云优势。即使云提供商被攻破,数据也会得到充分保护。
英文摘要
As higher education institutions consider moving services to the cloud to save costs and improve collaboration, significant challenges to successful large-scale adoption still exist. Institutions are unwilling to risk cloud deployment because provable technological defenses have thus far been lacking. Control over sensitive data is relinquished without the institution's knowledge, liability is shifted and data breach risks are significantly increased. Further, regulatory-sensitive data has become an increasingly attractive target. Recent history shows one major breach every few weeks, with an alarming increase in frequency. This project directly addresses this significant challenge by transitioning to practice -- through an educational campus pilot -- searchable cloud storage and collaboration tools with full in-cloud privacy, at-runtime security and no shift in liability for educators and students. The pilot provides secure cloud storage to 24,500 students and 2,500 educators. It constitutes a testbed for deploying secure protocols in a live environment via the participation of researchers and students in its operation. Extensive data dissemination for academic research purposes is an integral part of the pilot. Collected data points serve as significant knowledge repositories not only in the security community but also in the storage and cloud research communities. The project will result in the creation of a significant number of trust and security-related information technology jobs which must remain stateside to maintain the economic and political security of the United States. The project trains students and contributes to the creation of a skilled cyber-security domestic workforce available to fulfill our nation's needs. The project provides new course material and involves underrepresented groups, including at least one female PhD student.The technical underpinnings of the work rely on new mechanisms that ensure data is strongly encrypted before leaving trusted client premises while allowing users to still securely collaborate, query, share, synchronize, search, backup etc. Contrary to conventional wisdom, the project constructs a secure design that is also truly practical, but would not have been feasible with a server-centric approach in which search operations are performed server-side on encrypted data and are computationally expensive and necessarily limited in expressiveness. Instead, the pilot is based on an efficient design in which operations are distributed to client-side logic in a scalable, efficient manner, operating orders of magnitude faster than the equivalent server code on encrypted data. To further optimize processing, the system enables clients to leverage each other's work (such as indexing) in a distributed secure manner, through cloud-mediated conduits and mechanisms. Overall, the system ensures the cloud cannot ever access user data or see user search queries. Ultimately, clients receive all cloud benefits while ensuring full regulatory compliance. Even if the cloud provider is breached, data is fully protected.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SaTC: CORE: Small: Efficient Plausible Deniability Systems
  • 批准号:
    2052951
  • 项目类别:
    Standard Grant
  • 资助金额:
    $49.97万
  • 财政年份:
    2021
  • 负责人:
    Radu Sion
  • 依托单位:
NSFSaTC-BSF: TWC: Small: Practical Plausibly Deniable Encryption through Low-Level Storage Device Behavior
  • 批准号:
    1526707
  • 项目类别:
    Standard Grant
  • 资助金额:
    $50.0万
  • 财政年份:
    2015
  • 负责人:
    Radu Sion
  • 依托单位:
CSR: Small: Collaborative Research: Sensorprint: Hardware-Enforced Information Authentication for Mobile Systems
  • 批准号:
    1526102
  • 项目类别:
    Standard Grant
  • 资助金额:
    $25.0万
  • 财政年份:
    2015
  • 负责人:
    Radu Sion
  • 依托单位:
CSR: Small: Collaborative Research: Enabling Cost-Effective Cloud HPC
  • 批准号:
    1318572
  • 项目类别:
    Standard Grant
  • 资助金额:
    $15.0万
  • 财政年份:
    2013
  • 负责人:
    Radu Sion
  • 依托单位:
海外基金