Collaborative Research: CICI: Secure and Resilient Architecture: Data Integrity Assurance and Privacy Protection Solutions for Secure Interoperability of Cloud Resources
Collaborative Research: CICI: Secure and Resilient Architecture: Data Integrity Assurance and Privacy Protection Solutions for Secure Interoperability of Cloud Resources
批准号:
1642133
负责人:
Xiao Qin
金额:
$64.04万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2016
资助国家:
美国
项目状态:
已结题
起止时间:
2016-10-01 至 2021-09-30
中文摘要
云计算为用户提供了许多明显的好处,包括可伸缩性和降低系统采购成本。然而,当科学研究人员从云中访问数据进行实验或分析时,数据安全、完整性和隐私正成为他们的主要担忧。此外,由于数据的敏感性(例如医疗记录)或其价值,数据所有者可能不想将其数据透露给云服务提供商。因此,重要的是创建云数据完整性保证和隐私保护解决方案,帮助用户全面接受云服务并保护网络基础设施资源。有了云数据库,数据所有者可以存储从各种来源收集的大规模数据集。然后,用户可以发起查询,检索用于进行研究和实验的数据记录。然而,对查询结果的准确性有几个可能的威胁。例如,云数据库可能会遭到破坏,存储的数据可能会被篡改。云服务器可能出现故障,导致云数据库无意中返回不完整的查询结果。客户不太可能知道这种不正确或不完整的查询结果。因此,错误的数据可能被用于随后的科学实验或分析,这可能导致错误的结果。云数据库查询完整性保证是安全可信的端到端科学工作流的关键问题。这项工作以隐私友好的方式处理这些问题,建立在对加密数据的加密查询之上。这是实现数据隐私和数据完整性的关键。数据来源--数据的历史及其处理方式--也是科学工作流程的一个重要方面。然而,保护来源以提供完整性、隐私和机密性保证也是具有挑战性的,这使得许多科学工作流很难提供科学数据和查询结果的可验证来源历史。有了云,无论是数据还是来源,都很难提供这样的保证。该项目支持对云中存储和计算的所有数据和结果的来源信息进行安全收集、存储、传输和验证的基础设施支持。这种可核实的出处为科学工作流程提供了好处,通过可核实的历史和结果使这一过程更值得信赖。研究团队创建了一个查询完整性保证、数据隐私保护和可验证来源框架,为支持安全的云服务提供了一系列解决方案。该项目通过尝试新的云数据安全方法,实现了以下目标:(1)开发基于Voronoi图的完整性保证技术;(2)设计云数据库数据隐私保护方法;(3)对查询完整性保证和查询评估成本之间的权衡进行建模;(4)实现安全的云数据来源机制;(5)实现一个原型系统,其中所有组件都集成用于安全和性能评估。
英文摘要
Cloud computing provides many clear benefits for users, including scalability and reduced system acquisition cost. However, data security, integrity and privacy are becoming major concerns for scientific researchers when they access data from the cloud to conduct experiments or analytics. In addition, data owners may not want to reveal their data to cloud service providers either because of the sensitivity of the data (e.g., medical records) or because of its value. Therefore, it is important to create cloud data integrity assurance and privacy protection solutions that help users fully embrace cloud services as well as protect cyberinfrastructure resources. With a cloud database, data owners can store large-scale datasets collected from various sources. Users can then launch queries retrieving the data records for conducting research and experiments. However, there are several possible threats to query result accuracy. For example, a cloud database could be compromised and the stored data could be tampered with. There could be a malfunction in the cloud server, so that the cloud database inadvertently returns incomplete query results. It is unlikely that the client would be aware of such incorrect or incomplete query results. Consequently, erroneous data could be employed in subsequent scientific experiments or analyses, which could lead to false results. Cloud database query integrity assurance is critical issue that underpins a secure and trustworthy end-to-end scientific workflow. This work approaches these problems in a privacy-friendly manner, building on top of encrypted queries over encrypted data. This is key for achieving both data privacy and data integrity. Data provenance - the history of the data and how its been handled - is also an important aspect of scientific workflows. However, securing the provenance to provide integrity, privacy, and confidentiality guarantees is also challenging, making it hard for many scientific workflows to provide a verifiable provenance history of scientific data and query results. With clouds, providing such guarantees is difficult for both data and provenance. This project enables infrastructural support for secure collection, storage, transmission, and verification of provenance information for all data and results stored and computed in the cloud. The availability of such verifiable provenance offers benefits to scientific workflows, making the process more trustworthy via verifiable history and results. The research team creates a query integrity assurance, data privacy protection, and verifiable provenance framework which provides an array of solutions for supporting secure cloud services. This project contributes to the cybersecurity research community by piloting novel cloud data security approaches that accomplish the following goals: (1) developing Voronoi diagram‐based integrity assurance techniques, (2) designing cloud database data privacy protection methods, (3) modeling the trade off between query integrity assurance and query evaluation costs, (4) realizing secure cloud data provenance mechanisms, and (5) implementing a prototype system, where all the components are integrated for security and performance evaluation.
期刊论文(30)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
10.1109/tps-isa50397.2020.00044
发表时间:
2020-10
期刊:
2020 Second IEEE International Conference on Trust, Privacy and Security in Intelligent Systems and Applications (TPS-ISA)
影响因子:
--
作者:
[Jianzhou Mao;T. Cao;Xiaopu Peng;T. Bhattacharya;Wei-Shinn Ku;X. Qin]
通讯作者:
Jianzhou Mao;T. Cao;Xiaopu Peng;T. Bhattacharya;Wei-Shinn Ku;X. Qin
DOI:
10.1016/j.future.2017.02.043
发表时间:
2020-04-01
期刊:
FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE
影响因子:
7.5
作者:
[Zhou, Yi, Taneja, Shubbhi, Zhang, Jifu]
通讯作者:
Zhang, Jifu
DOI:
10.1109/icnp.2017.8117531
发表时间:
2017-10
期刊:
2017 IEEE 25th International Conference on Network Protocols (ICNP)
影响因子:
--
作者:
[Kazuya Sakai;Min-Te Sun;Wei-Shinn Ku;Jie Wu]
通讯作者:
Kazuya Sakai;Min-Te Sun;Wei-Shinn Ku;Jie Wu
DOI:
10.1109/twc.2019.2928801
发表时间:
2019-07
期刊:
IEEE Transactions on Wireless Communications
影响因子:
10.4
作者:
[Kazuya Sakai;Min-Te Sun;Wei-Shinn Ku;Jie Wu;T. Lai]
通讯作者:
Kazuya Sakai;Min-Te Sun;Wei-Shinn Ku;Jie Wu;T. Lai
DOI:
10.1109/jsyst.2018.2865571
发表时间:
2019-06
期刊:
IEEE Systems Journal
影响因子:
4.4
作者:
[Kazuya Sakai;Min-Te Sun;Wei-Shinn Ku;Hua Lu;T. Lai]
通讯作者:
Kazuya Sakai;Min-Te Sun;Wei-Shinn Ku;Hua Lu;T. Lai
共 30 条
III: Small: Indoor Spatial Query Evaluation and Trajectory Tracking with Bayesian Filtering Techniques
-
批准号:1618669
-
项目类别:Continuing Grant
-
资助金额:$50.0万
-
财政年份:2016
-
负责人:Xiao Qin
-
依托单位:
CAREER: Multicore-Based Parallel Disk Systems for Large-Scale Data-Intensive Computing
-
批准号:0845257
-
项目类别:Standard Grant
-
资助金额:$40.0万
-
财政年份:2009
-
负责人:Xiao Qin
-
依托单位:
QoSec: A Novel Middleware-Based Approach to Teaching Computer Security Courses
-
批准号:0837341
-
项目类别:Standard Grant
-
资助金额:$15.0万
-
财政年份:2009
-
负责人:Xiao Qin
-
依托单位:
CSR: Small: Collaborative Research: FastStor: Data-Mining-Based Multilayer Prefetching for Hybrid Storage Systems
-
批准号:0917137
-
项目类别:Standard Grant
-
资助金额:$20.0万
-
财政年份:2009
-
负责人:Xiao Qin
-
依托单位:
BUD: A Buffer-Disk Architecture for Energy Conservation in Parallel Disk Systems
-
批准号:0742187
-
项目类别:Standard Grant
-
资助金额:$0.0万
-
财政年份:2007
-
负责人:Xiao Qin
-
依托单位:
Mathematical reliability models for energy-efficient parallel disk systems
-
批准号:0757778
-
项目类别:Continuing Grant
-
资助金额:$0.0万
-
财政年份:2007
-
负责人:Xiao Qin
-
依托单位:
Mathematical reliability models for energy-efficient parallel disk systems
-
批准号:0713895
-
项目类别:Continuing Grant
-
资助金额:$15.0万
-
财政年份:2007
-
负责人:Xiao Qin
-
依托单位:
BUD: A Buffer-Disk Architecture for Energy Conservation in Parallel Disk Systems
-
批准号:0702781
-
项目类别:Standard Grant
-
资助金额:$30.0万
-
财政年份:2007
-
负责人:Xiao Qin
-
依托单位:
国内基金
海外基金
登录
查看更多内容
Research on Quantum Field Theory without a Lagrangian Description
-
批准号:24ZR1403900
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:SATOSHI NAWATA
-
依托单位:
Cell Research
-
批准号:31224802
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2012
-
负责人:程磊
-
依托单位:
Cell Research
-
批准号:31024804
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2010
-
负责人:程磊
-
依托单位:
Cell Research (细胞研究)
-
批准号:30824808
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2008
-
负责人:张爱兰
-
依托单位:
Research on the Rapid Growth Mechanism of KDP Crystal
-
批准号:10774081
-
项目类别:面上项目
-
资助金额:45.0万元
-
批准年份:2007
-
负责人:滕冰
-
依托单位: