SaTC: CORE: Small: Secure Cloud Storage Verification Methods
SaTC:核心:小型:安全云存储验证方法
基本信息
- 批准号:1813401
- 负责人:
- 金额:$ 50万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2018
- 资助国家:美国
- 起止时间:2018-08-15 至 2023-07-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
With the continuously decreasing costs of cloud services, many organizations including government agencies, healthcare providers, financial institutions, universities, and enterprises outsource large data repositories to cloud service providers (CSPs). Doing this relieves organizations from the financial burden of deploying and maintaining in-house data infrastructures. However, storing data with third parties exposes organizations to legal and financial liabilities should the data leak, become unavailable, or be lost. To reduce these risks, CSPs employ reliable storage technologies which are outlined in service level agreements (SLAs) negotiated with their clients. An SLA states data availability/reliability guarantees against misconfigurations, attacks, and any other disruption. Current SLAs, however, do not specify mechanisms for verifying that the CSP is adhering to the SLA terms. Accidental misconfigurations or attacks can lead to irrecoverable data loss that is detected only long after it has occurred. Moreover, economically motivated CSPs may choose to circumvent the SLA to reduce their operational costs. This project aims to design and test auditing mechanisms for provably and efficiently verifying adherence to SLA terms. The effort is well-aligned with national priorities on critical infrastructure security and resilience. It will result in cloud architectures, storage algorithms, and network and security protocols that strengthen the security, privacy, and usability of cloud storage systems, advancing the state-of-the-art on reliable and secure data storage. The project team will also use the work to inform the development of related courses and a cybersecurity certificate program, as well as supporting outreach efforts to middle and high school students and to groups traditionally underrepresented in computer science.The research agenda is organized around two major activities. The first activity investigates storage verification methods that not only prove the existence of the outsourced data but also verify the storage of redundant information for recovering from attacks and failures. Achieving such high levels of assurance is challenging because redundant information can be easily regenerated on-the-fly whenever the CSP is challenged to prove its existence. Effective auditing mechanisms require the joint design of the verification, coding, and data recovery processes to optimize the security-reliability-resource-efficiency tradeoffs while preserving data privacy and supporting data updatability. The second activity explores the physical storage verification at multiple storage nodes within a data center and/or between data centers. The team approaches the physical storage and geodiversity verification problems from the realistic standpoint of utilizing bounds on the physical resources such as network delay (which can be set conservatively). This allows technology-agnostic storage verification methods that are future-proof. A core project goal is the integration of logical and physical storage verification methods under a single suite of protocols. This integration is jointly considered with practical operational aspects of cloud systems, including data maintenance, dynamic data update, and privacy preservation.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
随着云服务成本的不断降低,包括政府机构、医疗保健提供商、金融机构、大学和企业在内的许多组织将大型数据存储库外包给云服务提供商(csp)。这样做可以减轻组织部署和维护内部数据基础设施的财务负担。但是,如果数据泄露、不可用或丢失,将数据存储在第三方会使组织承担法律和财务责任。为了降低这些风险,云计算服务提供商采用可靠的存储技术,这些技术在与客户协商的服务水平协议(sla)中概述。SLA声明数据可用性/可靠性保证,防止错误配置、攻击和任何其他中断。但是,当前的SLA并没有指定验证CSP是否遵守SLA条款的机制。意外的错误配置或攻击可能导致无法恢复的数据丢失,而这种丢失只有在发生很久之后才会被检测到。此外,出于经济动机的csp可能会选择规避SLA以降低其运营成本。该项目旨在设计和测试审计机制,以有效地验证SLA条款的遵守情况。这项工作与国家在关键基础设施安全和复原力方面的优先事项完全一致。它将产生云架构、存储算法、网络和安全协议,增强云存储系统的安全性、隐私性和可用性,推动可靠和安全数据存储的发展。项目团队还将利用这项工作为相关课程和网络安全证书项目的开发提供信息,并支持面向初高中学生和传统上在计算机科学领域代表性不足的群体的推广工作。研究议程围绕两个主要活动展开。第一个活动调查存储验证方法,这些方法不仅证明外包数据的存在,而且还验证冗余信息的存储,以便从攻击和故障中恢复。实现如此高水平的保证是具有挑战性的,因为每当CSP面临证明其存在的挑战时,冗余信息很容易在动态中重新生成。有效的审计机制需要验证、编码和数据恢复过程的联合设计,以优化安全性-可靠性-资源效率的权衡,同时保护数据隐私并支持数据可更新性。第二个活动探索数据中心内和/或数据中心之间的多个存储节点的物理存储验证。该团队从现实的角度来处理物理存储和地理多样性验证问题,利用物理资源的界限,如网络延迟(可以保守设置)。这允许技术无关的存储验证方法是面向未来的。核心项目目标是在一套协议下集成逻辑和物理存储验证方法。这种集成与云系统的实际操作方面(包括数据维护、动态数据更新和隐私保护)联合考虑。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
项目成果
期刊论文数量(25)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Reed-Solomon Based Quasi-Cyclic LDPC Codes: Designs, Girth, Cycle Structure, and Reduction of Short Cycles
- DOI:10.1109/tcomm.2019.2916605
- 发表时间:2019-05
- 期刊:
- 影响因子:8.3
- 作者:Xin Xiao;B. Vasic;Shu Lin;K. Abdel-Ghaffar;W. Ryan
- 通讯作者:Xin Xiao;B. Vasic;Shu Lin;K. Abdel-Ghaffar;W. Ryan
AdaptiveFog: A Modelling and Optimization Framework for Fog Computing in Intelligent Transportation Systems
- DOI:10.1109/tmc.2021.3080397
- 发表时间:2021-06
- 期刊:
- 影响因子:7.9
- 作者:Yong Xiao;M. Krunz
- 通讯作者:Yong Xiao;M. Krunz
Joint Task Partitioning and User Association for Latency Minimization in Mobile Edge Computing Networks
- DOI:10.1109/tvt.2021.3091458
- 发表时间:2021-08-01
- 期刊:
- 影响因子:6.8
- 作者:Feng, Mingjie;Krunz, Marwan;Zhang, Wenhan
- 通讯作者:Zhang, Wenhan
Quasi-Cyclic LDPC Codes With Parity-Check Matrices of Column Weight Two or More for Correcting Phased Bursts of Erasures
- DOI:10.1109/tcomm.2021.3059001
- 发表时间:2021-05
- 期刊:
- 影响因子:8.3
- 作者:Xin Xiao;B. Vasic;Shu Lin;Juane Li;K. Abdel-Ghaffar
- 通讯作者:Xin Xiao;B. Vasic;Shu Lin;Juane Li;K. Abdel-Ghaffar
Trapping Set Analysis of Finite-Length Quantum LDPC Codes
有限长度量子 LDPC 码的陷阱集分析
- DOI:10.1109/isit45174.2021.9518154
- 发表时间:2021
- 期刊:
- 影响因子:0
- 作者:Raveendran, Nithin;Vasic, Bane
- 通讯作者:Vasic, Bane
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Loukas Lazos其他文献
Perfect contextual information privacy in WSNs undercolluding eavesdroppers
无线传感器网络中完美的上下文信息隐私,避免串通窃听者
- DOI:
10.1145/2462096.2462112 - 发表时间:
2013 - 期刊:
- 影响因子:0
- 作者:
Alejandro Proaño;Loukas Lazos - 通讯作者:
Loukas Lazos
Passive Attacks on a Class of Authentication Protocols for RFID
对一类 RFID 身份验证协议的被动攻击
- DOI:
10.1007/978-3-540-76788-6_9 - 发表时间:
2007 - 期刊:
- 影响因子:0
- 作者:
Basel Alomair;Loukas Lazos;R. Poovendran - 通讯作者:
R. Poovendran
Reactive Identification of Misbehavior in Ad Hoc Networks Based on Random Audits
基于随机审计的自组织网络中的不当行为的反应性识别
- DOI:
10.1109/sahcn.2008.87 - 发表时间:
2008 - 期刊:
- 影响因子:0
- 作者:
William Kozma;Loukas Lazos - 通讯作者:
Loukas Lazos
Secure Localization for Wireless Sensor Networks using Range-Independent Methods
使用范围无关方法的无线传感器网络的安全定位
- DOI:
10.1007/978-0-387-46276-9_8 - 发表时间:
2007 - 期刊:
- 影响因子:0
- 作者:
Loukas Lazos;R. Poovendran - 通讯作者:
R. Poovendran
Misbehavior in Multi-Channel MAC Protocols
多通道 MAC 协议中的不当行为
- DOI:
10.1109/tdsc.2018.2819170 - 发表时间:
2020 - 期刊:
- 影响因子:7.3
- 作者:
Yan Zhang;Loukas Lazos - 通讯作者:
Loukas Lazos
Loukas Lazos的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Loukas Lazos', 18)}}的其他基金
REU Site: CAT Vehicle: The Cognitive and Autonomous Test Vehicle
REU 网站:CAT 车辆:认知和自主测试车辆
- 批准号:
1950359 - 财政年份:2020
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
SpecEES: Secure and Fair Spectrum Sharing for Heterogeneous Coexistent Systems
SpecEES:异构共存系统的安全和公平频谱共享
- 批准号:
1731164 - 财政年份:2017
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
CAREER: Domain-Specific Modeling Techniques for Cyber-Physical Systems
职业:网络物理系统的特定领域建模技术
- 批准号:
1253334 - 财政年份:2013
- 资助金额:
$ 50万 - 项目类别:
Continuing Grant
NeTS: Small: Efficient Techniques for Failure Recovery and Tomography in Networks
NeTS:小型:网络中故障恢复和层析成像的高效技术
- 批准号:
1117274 - 财政年份:2011
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
TC: Small: Enemies from Within: Thwarting Sophisticated Insider Attacks in Wireless Networks
TC:小:来自内部的敌人:阻止无线网络中复杂的内部攻击
- 批准号:
1016943 - 财政年份:2010
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
CAREER: Securing Channel Access in Multi-Channel Ad Hoc Networks
职业:保护多通道自组织网络中的通道访问
- 批准号:
0844111 - 财政年份:2009
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
相似国自然基金
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
- 批准号:82371765
- 批准年份:2023
- 资助金额:50 万元
- 项目类别:面上项目
锕系元素5f-in-core的GTH赝势和基组的开发
- 批准号:22303037
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
- 批准号:
- 批准年份:2022
- 资助金额:52 万元
- 项目类别:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
- 批准号:
- 批准年份:2022
- 资助金额:30 万元
- 项目类别:青年科学基金项目
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
- 批准号:
- 批准年份:2020
- 资助金额:55 万元
- 项目类别:
肌营养不良蛋白聚糖Core M3型甘露糖肽的精确制备及功能探索
- 批准号:92053110
- 批准年份:2020
- 资助金额:70.0 万元
- 项目类别:重大研究计划
Core-1-O型聚糖黏蛋白缺陷诱导胃炎发生并介导慢性胃炎向胃癌转化的分子机制研究
- 批准号:81902805
- 批准年份:2019
- 资助金额:20.5 万元
- 项目类别:青年科学基金项目
原始地球增生晚期的Core-merging大碰撞事件:地核增生、核幔平衡与核幔边界结构的新认识
- 批准号:41973063
- 批准年份:2019
- 资助金额:65.0 万元
- 项目类别:面上项目
CORDEX-CORE区域气候模拟与预估研讨会
- 批准号:41981240365
- 批准年份:2019
- 资助金额:1.5 万元
- 项目类别:国际(地区)合作与交流项目
RBM38通过协助Pol-ε结合、招募core调控HBV复制
- 批准号:31900138
- 批准年份:2019
- 资助金额:24.0 万元
- 项目类别:青年科学基金项目
相似海外基金
SaTC: CORE: Small: An evaluation framework and methodology to streamline Hardware Performance Counters as the next-generation malware detection system
SaTC:核心:小型:简化硬件性能计数器作为下一代恶意软件检测系统的评估框架和方法
- 批准号:
2327427 - 财政年份:2024
- 资助金额:
$ 50万 - 项目类别:
Continuing Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
- 批准号:
2338301 - 财政年份:2024
- 资助金额:
$ 50万 - 项目类别:
Continuing Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
- 批准号:
2338302 - 财政年份:2024
- 资助金额:
$ 50万 - 项目类别:
Continuing Grant
SaTC: CORE: Small: NSF-DST: Understanding Network Structure and Communication for Supporting Information Authenticity
SaTC:核心:小型:NSF-DST:了解支持信息真实性的网络结构和通信
- 批准号:
2343387 - 财政年份:2024
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
NSF-NSERC: SaTC: CORE: Small: Managing Risks of AI-generated Code in the Software Supply Chain
NSF-NSERC:SaTC:核心:小型:管理软件供应链中人工智能生成代码的风险
- 批准号:
2341206 - 财政年份:2024
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: CORE: Small: Towards Secure and Trustworthy Tree Models
协作研究:SaTC:核心:小型:迈向安全可信的树模型
- 批准号:
2413046 - 财政年份:2024
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
SaTC: CORE: Small: Study, Detection and Containment of Influence Campaigns
SaTC:核心:小型:影响力活动的研究、检测和遏制
- 批准号:
2321649 - 财政年份:2023
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
SaTC: CORE: Small: Socio-Technical Approaches for Securing Cyber-Physical Systems from False Claim Attacks
SaTC:核心:小型:保护网络物理系统免受虚假声明攻击的社会技术方法
- 批准号:
2310470 - 财政年份:2023
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: CORE: Small: Investigation of Naming Space Hijacking Threat and Its Defense
协作研究:SaTC:核心:小型:命名空间劫持威胁及其防御的调查
- 批准号:
2317830 - 财政年份:2023
- 资助金额:
$ 50万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Small: Towards a Privacy-Preserving Framework for Research on Private, Encrypted Social Networks
协作研究:SaTC:核心:小型:针对私有加密社交网络研究的隐私保护框架
- 批准号:
2318843 - 财政年份:2023
- 资助金额:
$ 50万 - 项目类别:
Continuing Grant














{{item.name}}会员




