TWC: Medium: Automating Countermeasures and Security Evaluation Against Software Side-channel Attacks
TWC: Medium: Automating Countermeasures and Security Evaluation Against Software Side-channel Attacks
批准号:
1563697
负责人:
Yunsi Fei
金额:
$120.0万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2016
资助国家:
美国
项目状态:
已结题
起止时间:
2016-06-01 至 2021-05-31
中文摘要
侧信道攻击(SCA)已经成为各种不具有专用保护功能的加密实现面临的现实威胁。虽然已经发现并手动应用了许多有效的对策,但它们是特定于应用程序且劳动密集型的。此外,安全评估往往是不完整的,无法保证目标系统中的所有漏洞都已被这种手动对策识别和解决。本项目旨在转变侧信道攻击研究范式,提出构建针对软件侧信道攻击的信息泄露分析、多层次对策应用和形式化安全评估的自动化框架。所提出的框架提供了信息泄漏的通用可靠度量、自动对策的方法以及正式和彻底的评估方法。该方法将功率分析和基于缓存的定时攻击统一到一个框架中。它定义了信息泄漏的新度量,并使用它们在没有实现细节的情况下,在早期阶段自动识别给定密码系统的可能泄漏。传统的编译过程沿着优化安全性的新维度进行扩展,以生成侧信道弹性代码并确保其在运行时的安全执行。采用形式化方法保证了侧信道安全性处于一定的置信度。团队中的三位研究者为这项具有挑战性的跨学科研究带来了互补的专业知识,以开发先进的自动化框架和相关的软件工具、度量和方法。在安全系统架构师和软件开发人员寻求将可验证的SCA安全性构建到他们设计的广泛应用程序中时,该结果对他们都有很大的好处。该项目还在基础统计、形式化方法和实际系统安全性之间建立了新的协同作用。在pi开发的新课程中引入自动化工具,可以极大地提高学生的实践经验。该项目还利用东北大学的体验式教育模式,让本科生、女性和少数民族学生参与自主研究项目。
英文摘要
Side-channel attacks (SCA) have been a realistic threat to various cryptographic implementations that do not feature dedicated protection. While many effective countermeasures have been found and applied manually, they are application-specific and labor intensive. In addition, security evaluation tends to be incomplete, with no guarantee that all the vulnerabilities in the target system have been identified and addressed by such manual countermeasures. This SaTC project aims to shift the paradigm of side-channel attack research, and proposes to build an automation framework for information leakage analysis, multi-level countermeasure application, and formal security evaluation against software side-channel attacks.The proposed framework provides common sound metrics for information leakage, methodologies for automatic countermeasures, and formal and thorough evaluation methods. The approach unifies power analysis and cache-based timing attacks into one framework. It defines new metrics of information leakage and uses them to automatically identify possible leakage of a given cryptosystem at an early stage with no implementation details. The conventional compilation process is extended along the new dimension of optimizing for security, to generate side-channel resilient code and ensure its secure execution at run-time. Side-channel security is guaranteed to be at a certain confidence level with formal methods. The three investigators on the team bring complementary expertise to this challenging interdisciplinary research, to develop the advanced automation framework and the associated software tools, metrics, and methodologies. The outcome significantly benefits security system architects and software developers alike, in their quest to build verifiable SCA security into a broad range of applications they design. The project also builds new synergy among fundamental statistics, formal methods, and practical system security. The automation tools, when introduced in new courses developed by the PIs, help improving students' hands-on experience greatly. The project also leverages the experiential education model of Northeastern University to engage undergraduates, women, and minority students in independent research projects.
期刊论文(1)
专著(0)
科研奖励(0)
会议论文
DOI:
10.2478/popets-2022-0025
发表时间:
2021-11
期刊:
Proceedings on Privacy Enhancing Technologies
影响因子:
--
作者:
[Konstantinos Athanasiou;T. Wahl;A. Ding;Yunsi Fei]
通讯作者:
Konstantinos Athanasiou;T. Wahl;A. Ding;Yunsi Fei
EAGER: Side Channels Go Deep - Leveraging Deep Learning for Side-channel Analysis and Protection
-
批准号:2212010
-
项目类别:Standard Grant
-
资助金额:$30.0万
-
财政年份:2022
-
负责人:Yunsi Fei
-
依托单位:
SaTC: CORE: Medium: Protecting Confidentiality and Integrity of Deep Neural Networks against Side-Channel and Fault Attacks
-
批准号:1929300
-
项目类别:Standard Grant
-
资助金额:$120.0万
-
财政年份:2019
-
负责人:Yunsi Fei
-
依托单位:
Phase I IUCRC Northeastern University: Center for Hardware and Embedded System Security and Trust (CHEST)
-
批准号:1916762
-
项目类别:Continuing Grant
-
资助金额:$75.0万
-
财政年份:2019
-
负责人:Yunsi Fei
-
依托单位:
Planning IUCRC Northeastern University: Center for Hardware and Embedded System Security and Trust (CHEST)
-
批准号:1747748
-
项目类别:Standard Grant
-
资助金额:$1.5万
-
财政年份:2018
-
负责人:Yunsi Fei
-
依托单位:
TWC: Medium: Collaborative: A Unified Statistics-Based Framework for Side-Channel Attack Analysis and Security Evaluation of Cryptosystems
-
批准号:1314655
-
项目类别:Standard Grant
-
资助金额:$52.21万
-
财政年份:2013
-
负责人:Yunsi Fei
-
依托单位:
MRI: Development of a Testbed for Side Channel Analysis and Security Evaluation (TeSCASE)
-
批准号:1337854
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2013
-
负责人:Yunsi Fei
-
依托单位:
A Multi-level/multi-faceted Framework for Energy-efficient Application-Specific Instruction Set Processor Synthesis
-
批准号:0541102
-
项目类别:Continuing Grant
-
资助金额:$27.5万
-
财政年份:2006
-
负责人:Yunsi Fei
-
依托单位:
海外基金