EAGER: Protecting Data Access Pattern Privacy in Hybrid Cloud Storage Systems
EAGER:保护混合云存储系统中的数据访问模式隐私
基本信息
- 批准号:1844591
- 负责人:
- 金额:$ 24.98万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2019
- 资助国家:美国
- 起止时间:2019-01-01 至 2021-12-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Cloud-based storage services are gaining increasing popularity for their attractive pay-as-you-go model and high availability, reliability and economic efficiency. Meanwhile, there is an increasing privacy consciousness among users regarding this storage paradigm. While encryption provides some protection for data privacy, it cannot protect data access patterns, which can reveal private information about cloud storage clients. In particular, a curious owner or employee of a cloud storage service or an attacker invading the system can observe a client's access patterns, develop a model relating the patterns to the client's activities and later on use the model and observed access patterns to infer or predict the client's activities. Although several schemes have been proposed to protect the access patterns, in particular Oblivious Random Access Memory (RAM), it is hard to put these into practice owing to the high communication, storage, or computational overheads they incur. Towards addressing this problem, the project aims to offer an efficient, scalable and practical solution using Oblivious RAM that can protect the privacy of access pattern and can seamlessly integrate with existing cloud storage infrastructures. Specifically, the project leverages the emerging hybrid cloud storage architecture that has a cloud storage gateway with a moderate level of resource at the client side, the well-known reference locality principle for data access, and the availability of multiple independent cloud storage servers in the market. The project would benefit the community by enhancing the users' awareness of security and privacy risks in using cloud services and providing them with user-friendly protection tools so that they benefit from using such services with confidence. The project designs a new hierarchical, Oblivious RAM storage system to include multiple layers of Oblivious RAM modules, each of which is optimized for different performance metrics depending on its niche on the hierarchy; hence, the hierarchy as whole can attain high efficiency in communication, storage and computation simultaneously. The project formalizes the problem of protecting the data access pattern for the whole hierarchy of Oblivious RAM modules, and develops novel algorithms to solve the problem. The project also aims to deliver a set of provably-secure Oblivious RAM algorithms optimized for short data access delay or low server-side storage overhead, and a set of provably-secure algorithms for planning an optimal architecture for a hierarchy of Oblivious RAM modules, configuring the hierarchy and coordinating the operations of all Oblivious RAM modules in the hierarchy.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
基于云的存储服务因其诱人的即付即用模式以及高可用性、可靠性和经济效率而越来越受欢迎。与此同时,用户对这种存储模式的隐私意识也在不断增强。虽然加密为数据隐私提供了一些保护,但它无法保护数据访问模式,因为数据访问模式可能会泄露有关云存储客户端的私人信息。特别是,好奇的云存储服务的所有者或员工或入侵系统的攻击者可以观察客户端的访问模式,开发将模式与客户端的活动相关联的模型,并在以后使用该模型和观察到的访问模式来推断或预测客户端的活动。虽然已经提出了几种方案来保护访问模式,特别是不经意的随机存取存储器(RAM),但由于它们引起的高通信、存储或计算开销,这些方案很难付诸实践。为了解决这一问题,该项目旨在提供一种高效、可扩展和实用的解决方案,使用不经意的RAM来保护访问模式的隐私,并可以与现有的云存储基础设施无缝集成。具体地说,该项目利用了新兴的混合云存储架构,该架构具有一个云存储网关,在客户端具有中等水平的资源,众所周知的数据访问参考位置原则,以及市场上多个独立云存储服务器的可用性。该项目将提高用户对使用云服务的安全和隐私风险的认识,并为他们提供方便使用的保护工具,使他们能够放心地使用该等服务,从而使社区受益。该项目设计了一种新的层次化的不经意RAM存储系统,包括多层不经意RAM模块,每个模块根据其在层次结构上的利基位置针对不同的性能指标进行优化,从而使层次结构作为一个整体能够同时达到通信、存储和计算的高效率。该项目将保护整个不经意RAM模块层次的数据访问模式的问题形式化,并开发了解决该问题的新算法。该项目还旨在提供一套针对短数据访问延迟或低服务器端存储开销进行优化的可证明安全的不经意RAM算法,以及一套可证明安全的算法,用于规划不经意RAM模块层次结构的最佳体系结构,配置层次结构并协调层次结构中所有不经意RAM模块的操作。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
项目成果
期刊论文数量(6)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Efficient and Accountable Oblivious Cloud Storage with Three Servers
- DOI:10.1109/cns.2019.8802848
- 发表时间:2019-06
- 期刊:
- 影响因子:0
- 作者:Qiumao Ma;Wensheng Zhang
- 通讯作者:Qiumao Ma;Wensheng Zhang
Game Theoretic Approach for Secure and Efficient Heavy-Duty Smart Contracts
- DOI:10.1109/cns48642.2020.9162290
- 发表时间:2020-06
- 期刊:
- 影响因子:0
- 作者:Pinglan Liu;Wensheng Zhang
- 通讯作者:Pinglan Liu;Wensheng Zhang
A Practical Oblivious Cloud Storage System based on TEE and Client Gateway
基于TEE和客户端网关的实用Oblivious云存储系统
- DOI:10.1109/pst52912.2021.9647827
- 发表时间:2021
- 期刊:
- 影响因子:0
- 作者:Zhang, Wensheng
- 通讯作者:Zhang, Wensheng
Optimizing Fund Allocation for Game-based Verifiable Computation Outsourcing
- DOI:10.1007/978-3-030-99191-3_6
- 发表时间:2021-03
- 期刊:
- 影响因子:0
- 作者:Pinglan Liu;Xiaojuan Ma;Wensheng Zhang
- 通讯作者:Pinglan Liu;Xiaojuan Ma;Wensheng Zhang
Octopus ORAM: An Oblivious RAM with Communication and Server Storage Efficiency
Octopus ORAM:一种具有通信和服务器存储效率的不经意的 RAM
- DOI:10.4108/eai.29-4-2019.162405
- 发表时间:2019
- 期刊:
- 影响因子:0
- 作者:Ma, Qiumao;Zhang, Wensheng
- 通讯作者:Zhang, Wensheng
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Wensheng Zhang其他文献
An HPLC tandem mass spectrometry for quantification of ET‐26‐HCl and its major metabolite in plasma and application to a pharmacokinetic study in rats
HPLC 串联质谱法定量血浆中 ET-26-HCl 及其主要代谢物及其在大鼠药代动力学研究中的应用
- DOI:
10.1016/j.jpba.2017.11.017 - 发表时间:
2018 - 期刊:
- 影响因子:3.4
- 作者:
Xu Chen;Wensheng Zhang;S. Rios;Miriam B Morkos;Xiaoli Ye;Gen Li;Xuehua Jiang;Zhijun Wang;Ling Wang - 通讯作者:
Ling Wang
Structure-aware siamese graph neural networks for encounter-level patient similarity learning
用于遭遇级别患者相似性学习的结构感知连体图神经网络
- DOI:
10.1016/j.jbi.2022.104027 - 发表时间:
2022-02 - 期刊:
- 影响因子:4.5
- 作者:
Yifan Gu;Xuebing Yang;Lei Tian;Hongyu Yang;Jicheng Lv;Chao Yang;Jinwei Wang;Jianing Xi;Guilan Kong;Wensheng Zhang - 通讯作者:
Wensheng Zhang
Reliability analysis approach for railway embankment slopes using response surface method based Monte Carlo simulation
基于蒙特卡罗模拟的响应面法铁路路基边坡可靠度分析方法
- DOI:
10.1007/s10706-022-02168-9 - 发表时间:
2022-05 - 期刊:
- 影响因子:1.7
- 作者:
Dehui Kong;Qiang Luo;Wensheng Zhang;Liangwei Jiang;Liang Zhang - 通讯作者:
Liang Zhang
Defending against cache consistency attacks in wireless ad hoc networks
防御无线自组织网络中的缓存一致性攻击
- DOI:
10.1016/j.adhoc.2007.02.005 - 发表时间:
2008 - 期刊:
- 影响因子:4.8
- 作者:
Wensheng Zhang;G. Cao - 通讯作者:
G. Cao
Feature extraction using maximum variance sparse mapping
使用最大方差稀疏映射进行特征提取
- DOI:
10.1007/s00521-010-0519-9 - 发表时间:
2012-11 - 期刊:
- 影响因子:0
- 作者:
Jin Liu;Bo Li;Wensheng Zhang - 通讯作者:
Wensheng Zhang
Wensheng Zhang的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Wensheng Zhang', 18)}}的其他基金
TWC: Small: Building Efficient and Accountable Multi-User ORAM Systems for Protecting Data Access Patterns
TWC:小型:构建高效且负责任的多用户 ORAM 系统以保护数据访问模式
- 批准号:
1422402 - 财政年份:2014
- 资助金额:
$ 24.98万 - 项目类别:
Standard Grant
Collaborative Research: Self-Sustainable Networking of Survivability-Heterogeneous Sensors
协作研究:生存性异构传感器的自我可持续网络
- 批准号:
1128312 - 财政年份:2011
- 资助金额:
$ 24.98万 - 项目类别:
Standard Grant
Collaborative Research: NeTS-NECO: Energy Replenishment for Wireless Sensor Networks
合作研究:NeTS-NECO:无线传感器网络的能量补充
- 批准号:
0831874 - 财政年份:2008
- 资助金额:
$ 24.98万 - 项目类别:
Standard Grant
Collaborative Research: CSR-DMSS: On-road Real-time Information Systems for driving safety atop VANET-WSM symbiosis
合作研究:CSR-DMSS:基于 VANET-WSM 共生的用于驾驶安全的道路实时信息系统
- 批准号:
0834593 - 财政年份:2008
- 资助金额:
$ 24.98万 - 项目类别:
Standard Grant
An Integrated Solution to Provide Privacy, Confidentiality, Integrity and Reliability Protection for Sensor Data Management
为传感器数据管理提供隐私、保密、完整性和可靠性保护的集成解决方案
- 批准号:
0716744 - 财政年份:2007
- 资助金额:
$ 24.98万 - 项目类别:
Standard Grant
相似海外基金
OAC Core: Data-driven Methods and Techniques For Protecting Research and Critical Cyberinfrastructure By Characterizing and Defending Against Ransomware
OAC 核心:通过表征和防御勒索软件来保护研究和关键网络基础设施的数据驱动方法和技术
- 批准号:
2348719 - 财政年份:2023
- 资助金额:
$ 24.98万 - 项目类别:
Standard Grant
Demonstrating the efficacy at scale of a novel data-protecting AI system for surfacing clinically-eligible patients for clinical trials
大规模展示新型数据保护人工智能系统的功效,为符合临床条件的患者提供临床试验
- 批准号:
10018100 - 财政年份:2022
- 资助金额:
$ 24.98万 - 项目类别:
Collaborative R&D
SOCAL: Privacy-protecting Sharing Of Clinical Data Across Laboratories
SOCAL:跨实验室临床数据的隐私保护共享
- 批准号:
10709531 - 财政年份:2022
- 资助金额:
$ 24.98万 - 项目类别:
SOCAL: Privacy-protecting Sharing Of Clinical Data Across Laboratories
SOCAL:跨实验室临床数据的隐私保护共享
- 批准号:
10522949 - 财政年份:2022
- 资助金额:
$ 24.98万 - 项目类别:
OAC Core: Data-driven Methods and Techniques For Protecting Research and Critical Cyberinfrastructure By Characterizing and Defending Against Ransomware
OAC 核心:通过表征和防御勒索软件来保护研究和关键网络基础设施的数据驱动方法和技术
- 批准号:
2104273 - 财政年份:2021
- 资助金额:
$ 24.98万 - 项目类别:
Standard Grant
Protecting Children and their Data Online: RegTech in Covid-19
保护儿童及其在线数据:Covid-19 中的监管科技
- 批准号:
90336 - 财政年份:2021
- 资助金额:
$ 24.98万 - 项目类别:
Collaborative R&D
SaTC: Frontiers: Collaborative: Protecting Personal Data Flow on the Internet
SaTC:前沿:协作:保护互联网上的个人数据流
- 批准号:
1956393 - 财政年份:2020
- 资助金额:
$ 24.98万 - 项目类别:
Continuing Grant
Development of an evaluation method of integrated safety technologies for protecting vulnerable road user based on actual accident data analysis
基于实际事故数据分析的保护弱势道路使用者综合安全技术评估方法的开发
- 批准号:
20K14847 - 财政年份:2020
- 资助金额:
$ 24.98万 - 项目类别:
Grant-in-Aid for Early-Career Scientists
SaTC: Frontiers: Collaborative: Protecting Personal Data Flow on the Internet
SaTC:前沿:协作:保护互联网上的个人数据流
- 批准号:
2103439 - 财政年份:2020
- 资助金额:
$ 24.98万 - 项目类别:
Continuing Grant
SaTC: Frontiers: Collaborative: Protecting Personal Data Flow on the Internet
SaTC:前沿:协作:保护互联网上的个人数据流
- 批准号:
1954224 - 财政年份:2020
- 资助金额:
$ 24.98万 - 项目类别:
Continuing Grant