CRII: SaTC: Towards Stronger and Verified Security for Real-World Cryptography

CRII:SaTC:为现实世界的密码学提供更强且经过验证的安全性

基本信息

  • 批准号:
    1755539
  • 负责人:
  • 金额:
    $ 17.45万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Standard Grant
  • 财政年份:
    2018
  • 资助国家:
    美国
  • 起止时间:
    2018-05-01 至 2023-04-30
  • 项目状态:
    已结题

项目摘要

Many real-world cryptographic schemes are based on the provable-security paradigm, certifying their security via some proof. However, in several important settings, existing proofs for the in-use constructions give weak security bounds, even to the extent that these results are not meaningful. Moreover, many proofs in the literature are buggy, giving false confidence on the security of constructions which are in fact vulnerable. Even worse, practitioners may introduce seemingly harmless optimizations into a secure scheme, only to find out later that these optimizations completely undermine the security of these schemes. This project aims to partially address these issues from several fronts: (1) improving security guarantees of important applications, (2) weeding out insecure optimizations of real-world protocols by devising attacks, and (3) developing tools for automatic verification of cryptographic proofs.This research aims to develop some message-recovery attacks on real-world format-preserving encryption schemes, which are widely used for encrypting credit-card numbers. The work targets some national standards as well as other constructions that are widely used. The research also studies how to provide meaningful provable security guarantees assuming that the discovered weaknesses are fixed properly. Furthermore, the research revisits the current approach for extracting high-quality randomness from random sources, with the goal to improve both security and efficiency. This is a fundamental problem in cryptography, as many cryptographic scenarios crucially rely on the use of randomness. Finally, the research investigates how to improve current methods of automatically verifying cryptographic proofs.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
许多现实世界的密码方案都是基于可证明安全的范式,通过一些证明来证明它们的安全性。然而,在几个重要的设置,现有的证明中使用的结构给出弱的安全界限,甚至到了这些结果是没有意义的程度。此外,文献中的许多证明是错误的,对实际上易受攻击的构造的安全性给予错误的信心。更糟糕的是,从业者可能会将看似无害的优化引入安全方案,但后来发现这些优化完全破坏了这些方案的安全性。该项目旨在从几个方面部分解决这些问题:(1)提高重要应用的安全性保证;(2)通过设计攻击来消除真实世界协议的不安全优化;(3)开发用于密码证明的自动验证工具。本研究旨在开发对真实世界格式保持加密方案的消息恢复攻击,其广泛用于加密信用卡号码。本工作针对一些国家标准以及其他广泛使用的结构。该研究还研究了如何提供有意义的可证明的安全保证,假设所发现的弱点被正确修复。此外,该研究重新审视了当前从随机源中提取高质量随机性的方法,目的是提高安全性和效率。这是密码学中的一个基本问题,因为许多密码学场景严重依赖于随机性的使用。最后,研究调查如何改善目前的自动验证密码proofs.This奖项的方法反映了NSF的法定使命,并已被认为是值得通过使用基金会的智力价值和更广泛的影响审查标准进行评估的支持。

项目成果

期刊论文数量(5)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Security of Streaming Encryption in Google's Tink Library
The Multi-user Security of GCM, Revisited: Tight Bounds for Nonce Randomization
Security Analysis of NIST CTR-DRBG
  • DOI:
    10.1007/978-3-030-56784-2_8
  • 发表时间:
    2020-08
  • 期刊:
  • 影响因子:
    0
  • 作者:
    V. Hoang;Yaobin Shen
  • 通讯作者:
    V. Hoang;Yaobin Shen
How to Break FF3 on Large Domains
如何在大型域上破解 FF3
The Curse of Small Domains: New Attacks on Format-Preserving Encryption
小域的诅咒:对格式保留加密的新攻击
  • DOI:
    10.1007/978-3-319-96884-1_8
  • 发表时间:
    2018
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Viet Tung Hoang, Stefano Tessaro
  • 通讯作者:
    Viet Tung Hoang, Stefano Tessaro
{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Viet Tung Hoang其他文献

Automated Analysis and Synthesis of Authenticated Encryption Schemes
认证加密方案的自动分析和综合
  • DOI:
  • 发表时间:
    2015
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Viet Tung Hoang;Jonathan Katz;A. Malozemoff
  • 通讯作者:
    A. Malozemoff

Viet Tung Hoang的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Viet Tung Hoang', 18)}}的其他基金

CAREER: New Analytic Frontiers for Symmetric Cryptography
职业:对称密码学的新分析前沿
  • 批准号:
    2046540
  • 财政年份:
    2021
  • 资助金额:
    $ 17.45万
  • 项目类别:
    Continuing Grant

相似海外基金

CRII: SaTC: Towards a Secure and Efficient Ethereum P2P Network with Client Diversity
CRII:SaTC:迈向具有客户端多样性的安全高效的以太坊 P2P 网络
  • 批准号:
    2347486
  • 财政年份:
    2024
  • 资助金额:
    $ 17.45万
  • 项目类别:
    Standard Grant
CRII: SaTC: Towards Understanding the Robustness of Graph Neural Networks against Graph Perturbations
CRII:SaTC:了解图神经网络对抗图扰动的鲁棒性
  • 批准号:
    2241713
  • 财政年份:
    2023
  • 资助金额:
    $ 17.45万
  • 项目类别:
    Standard Grant
CRII: SaTC: Towards Understanding and Defending Against New Waves of Online Hate
CRII:SaTC:理解和防御新一波的网络仇恨
  • 批准号:
    2245983
  • 财政年份:
    2023
  • 资助金额:
    $ 17.45万
  • 项目类别:
    Standard Grant
CRII: SaTC: Towards Data-effective and Cost-efficient Security Attack Detections
CRII:SaTC:迈向数据有效且经济高效的安全攻击检测
  • 批准号:
    2245968
  • 财政年份:
    2023
  • 资助金额:
    $ 17.45万
  • 项目类别:
    Standard Grant
CRII: SaTC: Towards Detecting and Mitigating Vulnerabilities
CRII:SaTC:致力于检测和缓解漏洞
  • 批准号:
    2153474
  • 财政年份:
    2022
  • 资助金额:
    $ 17.45万
  • 项目类别:
    Standard Grant
CRII: SaTC: RUI: Towards Trustworthy and Accountable IoT Data Marketplaces
CRII:SaTC:RUI:迈向值得信赖和负责任的物联网数据市场
  • 批准号:
    2153464
  • 财政年份:
    2022
  • 资助金额:
    $ 17.45万
  • 项目类别:
    Standard Grant
CRII: SaTC: Towards Trustworthy and Accountable IoT Data Marketplaces
CRII:SaTC:迈向值得信赖和负责任的物联网数据市场
  • 批准号:
    2231085
  • 财政年份:
    2022
  • 资助金额:
    $ 17.45万
  • 项目类别:
    Standard Grant
CRII: SaTC: Towards Secure and Privacy-preserving Input on Augmented Reality Systems
CRII:SaTC:增强现实系统的安全和隐私保护输入
  • 批准号:
    2153397
  • 财政年份:
    2022
  • 资助金额:
    $ 17.45万
  • 项目类别:
    Standard Grant
CRII: SaTC: Towards Understanding Typing Privacy: Vulnerabilities and Protection
CRII:SaTC:了解打字隐私:漏洞和保护
  • 批准号:
    1948547
  • 财政年份:
    2020
  • 资助金额:
    $ 17.45万
  • 项目类别:
    Standard Grant
CRII: SaTC: Towards Efficient and Scalable Crowdsourced Vulnerability-Discovery using Bug-Bounty Programs
CRII:SaTC:使用错误赏金计划实现高效且可扩展的众包漏洞发现
  • 批准号:
    1850510
  • 财政年份:
    2019
  • 资助金额:
    $ 17.45万
  • 项目类别:
    Standard Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了