课题基金 / 基金详情

SaTC: CORE: Small: Secure Cloud Storage Verification Methods

SaTC: CORE: Small: Secure Cloud Storage Verification Methods
SaTC:核心:小型:安全云存储验证方法
批准号:
1813401
负责人:
Loukas Lazos
金额:
$50.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2018
资助国家:
美国
项目状态:
已结题
起止时间:
2018-08-15 至 2023-07-31

项目摘要

项目成果

Loukas Lazos的其他基金

相似基金

相关文献

中文摘要
翻译
随着云服务成本的不断降低,包括政府机构、医疗保健提供商、金融机构、大学和企业在内的许多组织将大型数据存储库外包给云服务提供商(CSP)。这样做可以减轻组织部署和维护内部数据基础设施的财务负担。但是,与第三方一起存储数据会使组织在数据泄漏、不可用或丢失时承担法律的和财务责任。为了降低这些风险,CSP采用可靠的存储技术,这些技术在与客户协商的服务级别协议(SLA)中概述。SLA规定了数据可用性/可靠性保证,以防止错误配置、攻击和任何其他中断。然而,当前的SLA没有指定用于验证CSP遵守SLA条款的机制。意外的错误配置或攻击可能会导致无法恢复的数据丢失,这种情况只有在发生很久之后才能被检测到。此外,出于经济动机的CSP可能会选择绕过SLA以降低其运营成本。本项目旨在设计和测试审计机制,以可证明和有效地验证SLA条款的遵守情况。这一努力与关键基础设施安全和复原力方面的国家优先事项完全一致。它将产生云架构,存储算法以及网络和安全协议,这些协议将加强云存储系统的安全性,隐私性和可用性,推进可靠和安全数据存储的最新技术。项目团队还将利用这项工作为相关课程和网络安全证书课程的开发提供信息,并支持面向初中和高中学生以及传统上在计算机科学领域代表性不足的群体的外联工作。研究议程围绕两个主要活动组织。第一项活动研究存储验证方法,这些方法不仅可以证明外包数据的存在,还可以验证冗余信息的存储,以便从攻击和故障中恢复。实现如此高级别的保证是具有挑战性的,因为每当CSP被要求证明其存在时,冗余信息可以很容易地在运行中重新生成。有效的审计机制需要联合设计验证、编码和数据恢复过程,以优化安全性-可靠性-资源效率的权衡,同时保护数据隐私并支持数据更新。第二个练习探索数据中心内和/或数据中心之间的多个存储节点上的物理存储验证。 该团队从利用物理资源(如网络延迟(可以保守设置))的界限的现实角度来处理物理存储和地理多样性验证问题。这允许技术不可知的存储验证方法是未来的证明。项目的核心目标是在一套协议下集成逻辑和物理存储验证方法。该奖项反映了NSF的法定使命,通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
With the continuously decreasing costs of cloud services, many organizations including government agencies, healthcare providers, financial institutions, universities, and enterprises outsource large data repositories to cloud service providers (CSPs). Doing this relieves organizations from the financial burden of deploying and maintaining in-house data infrastructures. However, storing data with third parties exposes organizations to legal and financial liabilities should the data leak, become unavailable, or be lost. To reduce these risks, CSPs employ reliable storage technologies which are outlined in service level agreements (SLAs) negotiated with their clients. An SLA states data availability/reliability guarantees against misconfigurations, attacks, and any other disruption. Current SLAs, however, do not specify mechanisms for verifying that the CSP is adhering to the SLA terms. Accidental misconfigurations or attacks can lead to irrecoverable data loss that is detected only long after it has occurred. Moreover, economically motivated CSPs may choose to circumvent the SLA to reduce their operational costs. This project aims to design and test auditing mechanisms for provably and efficiently verifying adherence to SLA terms. The effort is well-aligned with national priorities on critical infrastructure security and resilience. It will result in cloud architectures, storage algorithms, and network and security protocols that strengthen the security, privacy, and usability of cloud storage systems, advancing the state-of-the-art on reliable and secure data storage. The project team will also use the work to inform the development of related courses and a cybersecurity certificate program, as well as supporting outreach efforts to middle and high school students and to groups traditionally underrepresented in computer science.The research agenda is organized around two major activities. The first activity investigates storage verification methods that not only prove the existence of the outsourced data but also verify the storage of redundant information for recovering from attacks and failures. Achieving such high levels of assurance is challenging because redundant information can be easily regenerated on-the-fly whenever the CSP is challenged to prove its existence. Effective auditing mechanisms require the joint design of the verification, coding, and data recovery processes to optimize the security-reliability-resource-efficiency tradeoffs while preserving data privacy and supporting data updatability. The second activity explores the physical storage verification at multiple storage nodes within a data center and/or between data centers. The team approaches the physical storage and geodiversity verification problems from the realistic standpoint of utilizing bounds on the physical resources such as network delay (which can be set conservatively). This allows technology-agnostic storage verification methods that are future-proof. A core project goal is the integration of logical and physical storage verification methods under a single suite of protocols. This integration is jointly considered with practical operational aspects of cloud systems, including data maintenance, dynamic data update, and privacy preservation.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(25)
专著(0)
科研奖励(0)
会议论文
DOI: 10.1109/tcomm.2019.2916605
发表时间: 2019-05
期刊: IEEE Transactions on Communications
影响因子: 8.3
作者: [Xin Xiao;B. Vasic;Shu Lin;K. Abdel-Ghaffar;W. Ryan]
通讯作者: Xin Xiao;B. Vasic;Shu Lin;K. Abdel-Ghaffar;W. Ryan
DOI: 10.1109/tmc.2021.3080397
发表时间: 2021-06
期刊: IEEE Transactions on Mobile Computing
影响因子: 7.9
作者: [Yong Xiao;M. Krunz]
通讯作者: Yong Xiao;M. Krunz
DOI: 10.1109/tvt.2021.3091458
发表时间: 2021-08-01
期刊: IEEE TRANSACTIONS ON VEHICULAR TECHNOLOGY
影响因子: 6.8
作者: [Feng, Mingjie, Krunz, Marwan, Zhang, Wenhan]
通讯作者: Zhang, Wenhan
DOI: 10.1109/tcomm.2021.3059001
发表时间: 2021-05
期刊: IEEE Transactions on Communications
影响因子: 8.3
作者: [Xin Xiao;B. Vasic;Shu Lin;Juane Li;K. Abdel-Ghaffar]
通讯作者: Xin Xiao;B. Vasic;Shu Lin;Juane Li;K. Abdel-Ghaffar
25
    REU Site: CAT Vehicle: The Cognitive and Autonomous Test Vehicle
    • 批准号:
      1950359
    • 项目类别:
      Standard Grant
    • 资助金额:
      $41.5万
    • 财政年份:
      2020
    • 负责人:
      Loukas Lazos
    • 依托单位:
    SpecEES: Secure and Fair Spectrum Sharing for Heterogeneous Coexistent Systems
    • 批准号:
      1731164
    • 项目类别:
      Standard Grant
    • 资助金额:
      $60.0万
    • 财政年份:
      2017
    • 负责人:
      Loukas Lazos
    • 依托单位:
    CAREER: Domain-Specific Modeling Techniques for Cyber-Physical Systems
    • 批准号:
      1253334
    • 项目类别:
      Continuing Grant
    • 资助金额:
      $46.04万
    • 财政年份:
      2013
    • 负责人:
      Loukas Lazos
    • 依托单位:
    NeTS: Small: Efficient Techniques for Failure Recovery and Tomography in Networks
    • 批准号:
      1117274
    • 项目类别:
      Standard Grant
    • 资助金额:
      $30.0万
    • 财政年份:
      2011
    • 负责人:
      Loukas Lazos
    • 依托单位:
    国内基金
    海外基金
    胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
    • 批准号:
      82371765
    • 项目类别:
      面上项目
    • 资助金额:
      50万元
    • 批准年份:
      2023
    • 负责人:
      谭广云
    • 依托单位:
    锕系元素5f-in-core的GTH赝势和基组的开发
    • 批准号:
      22303037
    • 项目类别:
      青年科学基金项目
    • 资助金额:
      30万元
    • 批准年份:
      2023
    • 负责人:
      鲁俊波
    • 依托单位:
    基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
    • 批准号:
      --
    • 项目类别:
      --
    • 资助金额:
      52万元
    • 批准年份:
      2022
    • 负责人:
      孙丙军
    • 依托单位:
    鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
    • 批准号:
      --
    • 项目类别:
      青年科学基金项目
    • 资助金额:
      30万元
    • 批准年份:
      2022
    • 负责人:
      叶成林
    • 依托单位: