课题基金 / 基金详情

CICI: RSARC: DICE - Data Insurance in the Cluster Environment

CICI: RSARC: DICE - Data Insurance in the Cluster Environment
CICI:RSARC:DICE - 集群环境中的数据保险
批准号:
1738912
负责人:
Zhi Wang
金额:
$59.03万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2017
资助国家:
美国
项目状态:
已结题
起止时间:
2017-08-15 至 2022-07-31

项目摘要

项目成果

Zhi Wang的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
High-performance, distributed computing has become indispensable in solving complex scientific, engineering, and business problems. The integrity of the data generated and stored on computer clusters is of undisputed importance to scientific research and business intelligence, as compromised data can lead to incorrect conclusions and decisions. Unfortunately, existing security mechanisms for high-performance and distributed computing systems are complex, inconsistent, insecure, and difficult to deploy. Many systems utilizing the current security mechanisms simply do not provide sufficient protection and remain vulnerable to even trivial attacks. For example, recent studies have found that thousands of unprotected database installations and computer clusters have been hacked. As such, there is a pressing need to improve the security of high-performance and distributed computing systems. This project develops a security framework for high-performance and distributed computing systems that employs strong modern cryptographic algorithms, and is easy to reason, deploy, and use without lengthy and error-prone configurations. The project consists of three major components: a container-based virtual cluster, a component to defend against side-channel attacks, and a secure execution ledger for auditing. The first component is the key to enabling authentication, authorization, and data protection for clusters without sacrificing usability or performance. The project team will build the virtual cluster based on the popular Docker container but enhance it with flexible key management, attack surface reduction, and security hardening, including defenses against side-channel attacks. Communications among nodes of a virtual cluster and I/O operations are transparently encrypted to protect the data in transition and at rest. The secure execution ledger provides a global holistic view of program execution in the whole system, allowing auditing the behavior of individual users as well as user groups. By tightly integrating these three components, the project seeks to achieve strong support for the four pillars of the cluster data security ? authentication, authorization, auditing, and data protection.
期刊论文(10)
专著(0)
科研奖励(0)
会议论文
Topology-custom UGAL routing on dragonfly
Dragonfly 上的拓扑自定义 UGAL 路由
DOI: 10.1145/3295500.3356208
发表时间: 2019
期刊: Storage and Analysis
影响因子: --
作者: [Rahman, Md Shafayat, Bhowmik, Saptarshi, Ryasnianskiy, Yevgeniy, Yuan, Xin, Lang, Michael]
通讯作者: Lang, Michael
Encrypted All-reduce on Multi-core Clusters
多核集群上的加密 All-reduce
DOI: 10.1109/ipccc51483.2021.9679399
发表时间: 2021
期刊: and Communications Conference (IPCCC
影响因子: --
作者: [Gavahi, Mohsen, Naser, Abu, Wu, Cong, Lahijani, Mehran Sadeghi, Wang, Zhi, Yuan, Xin]
通讯作者: Yuan, Xin
DOI: 10.1109/cluster.2019.8891033
发表时间: 2019
期刊: IEEE International Conference on Cluster Computing (CLUSTER
影响因子: --
作者: [Naser, Abu, Gavahi, Mohsen, Wu, Cong, Hoang, Viet Tung, Wang, Zhi, Yuan, Xin]
通讯作者: Yuan, Xin
DOI: --
发表时间: 2022
期刊:
影响因子: --
作者: [V. Hoang;Cong Wu;Xin Yuan]
通讯作者: V. Hoang;Cong Wu;Xin Yuan
9
    CAREER: Towards Trustworthy Operating Systems
    • 批准号:
      1453020
    • 项目类别:
      Continuing Grant
    • 资助金额:
      $49.97万
    • 财政年份:
      2015
    • 负责人:
      Zhi Wang
    • 依托单位:
    海外基金