FMitF: Track I: A Secure and Verifiable Commodity Hypervisor

FMITF:第一轨:安全且可验证的商品管理程序

基本信息

  • 批准号:
    1918400
  • 负责人:
  • 金额:
    $ 75万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Standard Grant
  • 财政年份:
    2019
  • 资助国家:
    美国
  • 起止时间:
    2019-07-01 至 2023-06-30
  • 项目状态:
    已结题

项目摘要

Hypervisors are widely deployed by cloud- computing providers to support virtual machines (VMs), but their growing complexity poses a security risk as large codebases contain many vulnerabilities. A compromised hypervisor risks the data and privacy of all its VMs -- an undesirable outcome for both cloud providers and users. In today's data-driven world, data confidentiality and integrity are of crucial importance. This project will design, implement, verify, and evaluate a fundamentally new approach to hypervisor design that provides a small, verified trusted computing base (TCB) for commodity hypervisors to protect the confidentiality and integrity of VMs running in the cloud. The project's novelties are a new hypervisor architecture and formal-verification framework. The project's impacts are providing a foundation for future innovations in the verification of systems software, especially for cloud-computing infrastructure, and verifying open-source virtualization technologies in Linux to drive research innovation in a way that can be adopted in commercial systems. This project designs a novel hypervisor architecture that partitions the hypervisor into a trusted core that performs basic virtualization, and an untrusted host that performs other hypervisor functionality and can be integrated with a host operating system. The investigators examine features of traditional hypervisors and identify only secure boot and basic CPU and memory virtualization as necessary for the core, resulting in a significantly simpler and verifiable hypervisor core. This project adopts a novel formal-verification framework named certified abstraction layers (CAL) to reason about the correctness (that is, the implementation meets its specification) and security (that is, the specification guarantees VM confidentiality and integrity) of the hypervisor core with an untrusted host. This project retrofits and verifies the Linux Kernel Virtual Machine (KVM) hypervisor, demonstrating the ability of these verification techniques to work in practice with commodity hypervisor software.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
云计算提供商广泛部署虚拟机管理程序来支持虚拟机(VM),但其日益增长的复杂性带来了安全风险,因为大型代码库包含许多漏洞。一个受损的虚拟机管理程序会危及其所有虚拟机的数据和隐私--这对云提供商和用户来说都是不可取的结果。在当今数据驱动的世界中,数据的机密性和完整性至关重要。该项目将设计、实施、验证和评估一种全新的虚拟机管理程序设计方法,为商用虚拟机管理程序提供一个小型的、经过验证的可信计算基础(TCB),以保护在云中运行的虚拟机的机密性和完整性。 该项目的创新之处在于新的hypervisor架构和形式验证框架。该项目的影响是为系统软件验证方面的未来创新奠定基础,特别是云计算基础设施,并验证Linux中的开源虚拟化技术,以推动研究创新,使其能够在商业系统中采用。该项目设计了一种新颖的虚拟机管理程序架构,该架构将虚拟机管理程序划分为执行基本虚拟化的可信核心和执行其他虚拟机管理程序功能并可与主机操作系统集成的不可信主机。调查人员研究了传统虚拟机管理程序的功能,并确定核心只需要安全的靴子和基本的CPU和内存虚拟化,从而产生了一个明显更简单和可验证的虚拟机管理程序核心。该项目采用了一种新的形式验证框架命名为认证抽象层(CAL)的原因的正确性(即,实现符合其规范)和安全性(即,规范保证虚拟机的机密性和完整性)的hypervisor核心与不可信的主机。该项目改造和验证了Linux内核虚拟机(KVM)虚拟机管理程序,展示了这些验证技术在实际中与商品虚拟机管理程序软件一起工作的能力。该奖项反映了NSF的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。

项目成果

期刊论文数量(12)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Design and Verification of the Arm Confidential Compute Architecture
  • DOI:
  • 发表时间:
    2022
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Xupeng Li;Xuheng Li;Christoffer Dall;Ronghui Gu;Jason Nieh;Yousuf Sait;Gareth Stockwell
  • 通讯作者:
    Xupeng Li;Xuheng Li;Christoffer Dall;Ronghui Gu;Jason Nieh;Yousuf Sait;Gareth Stockwell
UPGRADVISOR: Early Adopting Dependency Updates Using Hybrid Program Analysis and Hardware Tracing
UPGRADVISOR:使用混合程序分析和硬件跟踪尽早采用依赖项更新
Protecting Cloud Virtual Machines from Hypervisor and Host Operating System Exploits
  • DOI:
  • 发表时间:
    2019
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Shih-wei Li;John S. Koh;Jason Nieh
  • 通讯作者:
    Shih-wei Li;John S. Koh;Jason Nieh
CLN2INV: LEARNING LOOP INVARIANTS WITH CONTINUOUS LOGIC NETWORK
CLN2INV:使用连续逻辑网络学习循环不变量
A Secure and Formally Verified Linux KVM Hypervisor
  • DOI:
    10.1109/sp40001.2021.00049
  • 发表时间:
    2021-05
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Shih-wei Li;Xupeng Li;Ronghui Gu;Jason Nieh;J. Hui
  • 通讯作者:
    Shih-wei Li;Xupeng Li;Ronghui Gu;Jason Nieh;J. Hui
{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Jason Nieh其他文献

Aequitas: A Trusted P2P System for Paid Content Delivery
Aequitas:用于付费内容交付的可信 P2P 系统
  • DOI:
    10.7916/d8tx3p7b
  • 发表时间:
    2007
  • 期刊:
  • 影响因子:
    0
  • 作者:
    A. Sherman;Japinder Singh Chawla;Jason Nieh;C. Stein;Justin Sarma
  • 通讯作者:
    Justin Sarma
Group round robin
小组循环赛
Grouped distributed queues: distributed queue, proportional share multiprocessor scheduling
分组分布式队列:分布式队列,比例份额多处理器调度
Web browsing performance of wireless thin-client computing
无线瘦客户端计算的网页浏览性能
  • DOI:
  • 发表时间:
    2003
  • 期刊:
  • 影响因子:
    0
  • 作者:
    S. J. Yang;Jason Nieh;S. Krishnappa;Aparna Mohla;M. Sajjadpour
  • 通讯作者:
    M. Sajjadpour
Proceedings of the 11th international workshop on Network and operating systems support for digital audio and video
  • DOI:
  • 发表时间:
    2001
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Jason Nieh
  • 通讯作者:
    Jason Nieh

Jason Nieh的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Jason Nieh', 18)}}的其他基金

FMitF: Track I: Verifying System Software on an Arm Multiprocessor Hardware Model
FMITF:第一轨:在 Arm 多处理器硬件模型上验证系统软件
  • 批准号:
    2124080
  • 财政年份:
    2021
  • 资助金额:
    $ 75万
  • 项目类别:
    Standard Grant
TWC: TTP Option: Small: A Linux ARM Hypervisor for System Security
TWC:TTP 选项:小型:用于系统安全的 Linux ARM 虚拟机管理程序
  • 批准号:
    1422909
  • 财政年份:
    2014
  • 资助金额:
    $ 75万
  • 项目类别:
    Standard Grant
CSR: Medium: A Virtual Smartphone and Tablet System Architecture
CSR:媒介:虚拟智能手机和平板电脑系统架构
  • 批准号:
    1162447
  • 财政年份:
    2012
  • 资助金额:
    $ 75万
  • 项目类别:
    Continuing Grant
SHF: Medium: RacePro: Automatically Detecting API Races in Deployed Systems
SHF:中:RacePro:自动检测已部署系统中的 API 竞争
  • 批准号:
    1162021
  • 财政年份:
    2012
  • 资助金额:
    $ 75万
  • 项目类别:
    Standard Grant
Student Travel Support for the 2011 USENIX Annual Technical Conference
2011 年 USENIX 年度技术会议的学生旅行支持
  • 批准号:
    1137962
  • 财政年份:
    2011
  • 资助金额:
    $ 75万
  • 项目类别:
    Standard Grant
TC: Small: Improving System Security through Virtual Layered File Systems
TC:小型:通过虚拟分层文件系统提高系统安全性
  • 批准号:
    1018355
  • 财政年份:
    2010
  • 资助金额:
    $ 75万
  • 项目类别:
    Standard Grant
TC: Small: Exploiting Software Elasticity for Automatic Software Self-Healing
TC:小:利用软件弹性实现自动软件自我修复
  • 批准号:
    0914845
  • 财政年份:
    2009
  • 资助金额:
    $ 75万
  • 项目类别:
    Standard Grant
ITR - (NHS) - (int/dmc): Secure Remote Computing Services
ITR - (NHS) - (int/dmc):安全远程计算服务
  • 批准号:
    0426623
  • 财政年份:
    2004
  • 资助金额:
    $ 75万
  • 项目类别:
    Continuing Grant
Network Virtualization Mechanisms for Mobile Communication
移动通信网络虚拟化机制
  • 批准号:
    0240525
  • 财政年份:
    2003
  • 资助金额:
    $ 75万
  • 项目类别:
    Standard Grant
ITR: An Experimental Study of Thin-Client Computing Architectures
ITR:瘦客户端计算架构的实验研究
  • 批准号:
    0219943
  • 财政年份:
    2002
  • 资助金额:
    $ 75万
  • 项目类别:
    Continuing Grant

相似海外基金

MRI: Track 1 Acquisition of a 400 MHz NMR Spectrometer to Expand and Secure Solution NMR Spectroscopy at UConn with Facility Helium Stewardship
MRI:轨道 1 采购 400 MHz NMR 波谱仪,通过设施氦气管理来扩展和保护康涅狄格大学的 NMR 波谱解决方案
  • 批准号:
    2320586
  • 财政年份:
    2023
  • 资助金额:
    $ 75万
  • 项目类别:
    Standard Grant
Collaborative Research: RII Track-2 FEC: STORM: Data-Driven Approaches for Secure Electric Grids in Communities Disproportionately Impacted by Climate Change
合作研究:RII Track-2 FEC:STORM:受气候变化影响较大的社区中安全电网的数据驱动方法
  • 批准号:
    2316400
  • 财政年份:
    2023
  • 资助金额:
    $ 75万
  • 项目类别:
    Cooperative Agreement
Collaborative Research: RII Track-2 FEC: STORM: Data-Driven Approaches for Secure Electric Grids in Communities Disproportionately Impacted by Climate Change
合作研究:RII Track-2 FEC:STORM:受气候变化影响较大的社区中安全电网的数据驱动方法
  • 批准号:
    2316402
  • 财政年份:
    2023
  • 资助金额:
    $ 75万
  • 项目类别:
    Cooperative Agreement
Collaborative Research: RII Track-2 FEC: STORM: Data-Driven Approaches for Secure Electric Grids in Communities Disproportionately Impacted by Climate Change
合作研究:RII Track-2 FEC:STORM:受气候变化影响较大的社区中安全电网的数据驱动方法
  • 批准号:
    2316401
  • 财政年份:
    2023
  • 资助金额:
    $ 75万
  • 项目类别:
    Cooperative Agreement
FMitF: Track II: Bringing Verification-Aware Languages and Federated Authentication to Enable Secure Computing for Scientific Communities
FMITF:轨道 II:引入验证感知语言和联合身份验证,为科学界提供安全计算
  • 批准号:
    2319190
  • 财政年份:
    2023
  • 资助金额:
    $ 75万
  • 项目类别:
    Standard Grant
Collaborative Research: RII Track-2 FEC: STORM: Data-Driven Approaches for Secure Electric Grids in Communities Disproportionately Impacted by Climate Change
合作研究:RII Track-2 FEC:STORM:受气候变化影响较大的社区中安全电网的数据驱动方法
  • 批准号:
    2316399
  • 财政年份:
    2023
  • 资助金额:
    $ 75万
  • 项目类别:
    Cooperative Agreement
NSF Convergence Accelerator Track G: Autonomously Tunable Waveform-Agnostic Radio Adapter for Seamless and Secure Operation of DoD Devices Through Non-Cooperative 5G Networks
NSF 融合加速器轨道 G:自主可调波形无关无线电适配器,可通过非合作 5G 网络无缝、安全地操作国防部设备
  • 批准号:
    2226392
  • 财政年份:
    2022
  • 资助金额:
    $ 75万
  • 项目类别:
    Standard Grant
NSF Convergence Accelerator Track G: Building Resilient and Secure 5G Systems (BRASS)
NSF 融合加速器轨道 G:构建弹性且安全的 5G 系统 (BRASS)
  • 批准号:
    2226555
  • 财政年份:
    2022
  • 资助金额:
    $ 75万
  • 项目类别:
    Standard Grant
NSF Convergence Accelerator Track G: Privacy-preserving Intrusion-resilient Secure Multiparty-computation-based Overlay (PISMO) for Secure and Resilient Communication Through 5G
NSF 融合加速器轨道 G:隐私保护、抗入侵、基于安全多方计算的覆盖 (PISMO),通过 5G 实现安全和弹性通信
  • 批准号:
    2226457
  • 财政年份:
    2022
  • 资助金额:
    $ 75万
  • 项目类别:
    Standard Grant
CIVIC-PG Track B: Economic Resiliency through Mechanism Design and Secure Computing: MainStreetPulse: An Early Warning Platform for Monitoring and Supporting Main Street Businesses
CIVIC-PG 轨道 B:通过机制设计和安全计算实现经济弹性:MainStreetPulse:用于监控和支持大街业务的预警平台
  • 批准号:
    2228610
  • 财政年份:
    2022
  • 资助金额:
    $ 75万
  • 项目类别:
    Standard Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了