Collaborative Research: CPS: Medium: Timeliness vs. Trustworthiness: Balancing Predictability and Security in Time-Sensitive CPS Design
协作研究:CPS:中:及时性与可信度:在时间敏感的 CPS 设计中平衡可预测性和安全性
基本信息
- 批准号:2038726
- 负责人:
- 金额:$ 48万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2021
- 资助国家:美国
- 起止时间:2021-02-01 至 2025-01-31
- 项目状态:未结题
- 来源:
- 关键词:
项目摘要
Many cyber-physical systems (CPS) have real-time (RT) requirements. For these RT-CPS, such as a network of unmanned aerial vehicles that deliver packages to customers’ homes or a robot that performs/aides in cardiac surgery, deadline misses may result in economic losses or even fatal consequences. At the same time, as these RT-CPS interact with, and are depended on by, humans, they must also be trustworthy. The goal of this research is to design secure RT-CPS that are less complex, easier to analyze, and reliable for critical application domains such as defense, medicine, transportation, manufacturing, and agriculture, to name just a few. Since RT-CPS now permeate most aspects of our daily lives, especially in the smart city and internet-of-things (IoT) context, this research will improve confidence in automated systems by users. Research results will be disseminated to both academia and industry, and permit timely adoption since the hardware required in this research is already publicly available. This project will result in a pipeline of engineers and computer scientists who are well-versed in the interdisciplinary nature of securing RT-CPS, as well as course modules and red-teaming exercises for undergraduate students in all engineering disciplines and interactive learning modules and internship experience for K-12 students in D.C., Detroit, Dallas, and St. Louis.The goal of this research is to design secure RT-CPS from the ground up while explicitly accounting for physical dynamics of said RT-CPS at runtime to achieve resilience via prevention and detection of, and recovery from, attacks. This will be accomplished by (i) securing the scheduling infrastructure from the ground up, (ii) using a formal framework for trading off security against timeliness while accounting for system dynamics, and for the cost of security to be explicitly quantified, and (iii) performing state- and function-dependent on-demand recovery. Said RT-CPS will be able to proactively prevent attacks using moving target defenses, as well as detect and recover from attacks that cannot be avoided. This research will pave the way for RT-CPS and internet-of-things (IoT) to be implemented with confidence: their timely and correct operation guaranteed. Specific contributions of this research are: (i) a trusted scheduling infrastructure that can protect the integrity of the real-time tasks, the scheduler, its task queues, and I/O, and which can recover from (intentional) errors, (ii) a probabilistic real-time/security co-design framework that exploits trusted execution to protect the security of the real-time tasks, (iii) novel schedulability analysis techniques, (iv) an incremental recovery mechanism for continuous operation, and (v) validation on automated ground vehicles, drones, and robot arms. Contributions expanding the knowledge base will be made to the fields of CPS, IoT, real-time systems, security, and control systems.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
许多信息物理系统(CPS)都有实时(RT)要求。对于这些RT-CPS,例如将包裹递送到客户家中的无人驾驶飞行器网络或执行/辅助心脏手术的机器人,最后期限错过可能导致经济损失甚至致命后果。与此同时,由于这些RT-CPS与人类互动并被人类依赖,它们也必须是值得信赖的。本研究的目标是设计安全的RT-CPS,对于国防、医学、交通、制造和农业等关键应用领域来说,这些领域不太复杂、更容易分析且可靠,仅举几例。由于RT-CPS现在渗透到我们日常生活的大部分方面,特别是在智能城市和物联网(IoT)背景下,这项研究将提高用户对自动化系统的信心。研究结果将向学术界和工业界传播,并允许及时采用,因为这项研究所需的硬件已经公开。该项目将产生一批精通保护RT-CPS的跨学科性质的工程师和计算机科学家,以及所有工程学科的本科生的课程模块和红队练习,以及华盛顿特区K-12学生的互动学习模块和实习经验,本研究的目标是从头开始设计安全的RT-CPS,同时明确说明所述RT-CPS在运行时的物理动态,以通过预防和检测攻击以及从攻击中恢复来实现弹性。这将通过以下方式实现:(i)从底层开始保护调度基础设施,(ii)使用正式框架来权衡安全性和及时性,同时考虑系统动态,并明确量化安全成本,以及(iii)执行状态和功能依赖的按需恢复。RT-CPS将能够使用移动目标防御来主动预防攻击,并检测无法避免的攻击并从中恢复。这项研究将为RT-CPS和物联网(IoT)的实施铺平道路:保证其及时和正确的操作。这项研究的具体贡献是:(i)可信的调度基础设施,可以保护实时任务、调度器、其任务队列和I/O的完整性,并且可以从(故意)错误,(ii)利用可信执行来保护实时任务的安全性的概率实时/安全协同设计框架,(iii)新颖的可验证性分析技术,(iv)用于连续操作的增量恢复机制,以及(v)对自动地面车辆、无人机和机器人手臂的验证。该奖项反映了NSF的法定使命,通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
项目成果
期刊论文数量(2)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Survey of Control-flow Integrity Techniques for Real-time Embedded Systems
- DOI:10.1145/3538275
- 发表时间:2021-11
- 期刊:
- 影响因子:0
- 作者:Tanmaya Mishra;Thidapat Chantem;Ryan M. Gerdes
- 通讯作者:Tanmaya Mishra;Thidapat Chantem;Ryan M. Gerdes
Secure CV2X Using COTS Smartphones over LTE Infrastructure
在 LTE 基础设施上使用 COTS 智能手机保护 CV2X
- DOI:
- 发表时间:2023
- 期刊:
- 影响因子:0
- 作者:Mahadevegowda, Spandan;Gerdes, Ryan M;Chantem, Thidapat;Hu, Rose Q
- 通讯作者:Hu, Rose Q
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Thidapat Chantem其他文献
A Node and Load Allocation Algorithm for Resilient CPSs under Energy-Exhaustion Attack
- DOI:
- 发表时间:
2014 - 期刊:
- 影响因子:0
- 作者:
Thidapat Chantem - 通讯作者:
Thidapat Chantem
Secure Traffic Lights: Replay Attack Detection for Model-based Smart Traffic Controllers
安全交通灯:基于模型的智能交通控制器的重放攻击检测
- DOI:
- 发表时间:
2020 - 期刊:
- 影响因子:0
- 作者:
Pratham Oza;M. Foruhandeh;Ryan M. Gerdes;Thidapat Chantem - 通讯作者:
Thidapat Chantem
TEECheck: Securing Intra-Vehicular Communication Using Trusted Execution
TEECheck:使用可信执行保护车内通信
- DOI:
10.1145/3394810.3394822 - 发表时间:
2020 - 期刊:
- 影响因子:0
- 作者:
Tanmaya Mishra;Thidapat Chantem;Ryan M. Gerdes - 通讯作者:
Ryan M. Gerdes
EDF-hv: An Energy-Efficient Semi-Partitioned Approach for Hard Real-Time Systems
EDF-hv:一种用于硬实时系统的节能半分区方法
- DOI:
10.1145/2997465.2997491 - 发表时间:
2016 - 期刊:
- 影响因子:0
- 作者:
Jesse Patterson;Thidapat Chantem - 通讯作者:
Thidapat Chantem
An Efficient Knapsack-Based Approach for Calculating the Worst-Case Demand of AVR Tasks
一种基于背包的高效 AVR 任务最坏情况需求计算方法
- DOI:
- 发表时间:
2018 - 期刊:
- 影响因子:0
- 作者:
Sandeep Kumar Bijinemula;Aaron Willcock;Thidapat Chantem;N. Fisher - 通讯作者:
N. Fisher
Thidapat Chantem的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Thidapat Chantem', 18)}}的其他基金
CPS: Synergy: Collaborative Research: Semi-Automated Emergency Response System
CPS:协同:协作研究:半自动应急响应系统
- 批准号:
1545091 - 财政年份:2016
- 资助金额:
$ 48万 - 项目类别:
Standard Grant
CSR: Small: Collaborative Research: Exploiting Predictability & Interdependency of Physical Parameters for Resource-Efficient Integration of Real-Time Embedded Systems
企业社会责任:小型:协作研究:利用可预测性
- 批准号:
1618979 - 财政年份:2016
- 资助金额:
$ 48万 - 项目类别:
Standard Grant
CPS: Synergy: Collaborative Research: Semi-Automated Emergency Response System
CPS:协同:协作研究:半自动应急响应系统
- 批准号:
1658225 - 财政年份:2016
- 资助金额:
$ 48万 - 项目类别:
Standard Grant
CSR: Small: Collaborative Research: Reliability Driven Resource Management of Multi-Core Real-Time Embedded Systems
CSR:小型:协作研究:多核实时嵌入式系统的可靠性驱动资源管理
- 批准号:
1319718 - 财政年份:2013
- 资助金额:
$ 48万 - 项目类别:
Standard Grant
相似国自然基金
Research on Quantum Field Theory without a Lagrangian Description
- 批准号:24ZR1403900
- 批准年份:2024
- 资助金额:0.0 万元
- 项目类别:省市级项目
Cell Research
- 批准号:31224802
- 批准年份:2012
- 资助金额:24.0 万元
- 项目类别:专项基金项目
Cell Research
- 批准号:31024804
- 批准年份:2010
- 资助金额:24.0 万元
- 项目类别:专项基金项目
Cell Research (细胞研究)
- 批准号:30824808
- 批准年份:2008
- 资助金额:24.0 万元
- 项目类别:专项基金项目
Research on the Rapid Growth Mechanism of KDP Crystal
- 批准号:10774081
- 批准年份:2007
- 资助金额:45.0 万元
- 项目类别:面上项目
相似海外基金
Collaborative Research: CPS: NSF-JST: Enabling Human-Centered Digital Twins for Community Resilience
合作研究:CPS:NSF-JST:实现以人为本的数字孪生,提高社区复原力
- 批准号:
2420846 - 财政年份:2024
- 资助金额:
$ 48万 - 项目类别:
Standard Grant
Collaborative Research: CPS: Medium: Automating Complex Therapeutic Loops with Conflicts in Medical Cyber-Physical Systems
合作研究:CPS:中:自动化医疗网络物理系统中存在冲突的复杂治疗循环
- 批准号:
2322534 - 财政年份:2024
- 资助金额:
$ 48万 - 项目类别:
Standard Grant
Collaborative Research: CPS: NSF-JST: Enabling Human-Centered Digital Twins for Community Resilience
合作研究:CPS:NSF-JST:实现以人为本的数字孪生,提高社区复原力
- 批准号:
2420847 - 财政年份:2024
- 资助金额:
$ 48万 - 项目类别:
Standard Grant
Collaborative Research: CPS: Small: Risk-Aware Planning and Control for Safety-Critical Human-CPS
合作研究:CPS:小型:安全关键型人类 CPS 的风险意识规划和控制
- 批准号:
2423130 - 财政年份:2024
- 资助金额:
$ 48万 - 项目类别:
Standard Grant
Collaborative Research: CPS: Medium: Automating Complex Therapeutic Loops with Conflicts in Medical Cyber-Physical Systems
合作研究:CPS:中:自动化医疗网络物理系统中存在冲突的复杂治疗循环
- 批准号:
2322533 - 财政年份:2024
- 资助金额:
$ 48万 - 项目类别:
Standard Grant
Collaborative Research: CPS: Medium: Physics-Model-Based Neural Networks Redesign for CPS Learning and Control
合作研究:CPS:中:基于物理模型的神经网络重新设计用于 CPS 学习和控制
- 批准号:
2311084 - 财政年份:2023
- 资助金额:
$ 48万 - 项目类别:
Standard Grant
CPS: Medium: Collaborative Research: Provably Safe and Robust Multi-Agent Reinforcement Learning with Applications in Urban Air Mobility
CPS:中:协作研究:可证明安全且鲁棒的多智能体强化学习及其在城市空中交通中的应用
- 批准号:
2312092 - 财政年份:2023
- 资助金额:
$ 48万 - 项目类别:
Standard Grant
Collaborative Research: CPS: Medium: Sensor Attack Detection and Recovery in Cyber-Physical Systems
合作研究:CPS:中:网络物理系统中的传感器攻击检测和恢复
- 批准号:
2333980 - 财政年份:2023
- 资助金额:
$ 48万 - 项目类别:
Standard Grant
Collaborative Research: CPS: Medium: An Online Learning Framework for Socially Emerging Mixed Mobility
协作研究:CPS:媒介:社会新兴混合出行的在线学习框架
- 批准号:
2401007 - 财政年份:2023
- 资助金额:
$ 48万 - 项目类别:
Standard Grant
CPS: Medium: Collaborative Research: Robust Sensing and Learning for Autonomous Driving Against Perceptual Illusion
CPS:中:协作研究:针对自动驾驶对抗知觉错觉的鲁棒感知和学习
- 批准号:
2235231 - 财政年份:2023
- 资助金额:
$ 48万 - 项目类别:
Standard Grant