Collaborative Research: SaTC: CORE: Medium: Hybridizing Trusted Execution Environments and Secure Multiparty Computation
Collaborative Research: SaTC: CORE: Medium: Hybridizing Trusted Execution Environments and Secure Multiparty Computation
批准号:
2112751
负责人:
Ari Juels
金额:
$40.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2021
资助国家:
美国
项目状态:
已结题
起止时间:
2021-10-01 至 2024-09-30
中文摘要
随着敏感的数字信息激增,企业和政府对其不当使用的担忧与日俱增,出现了两种主要的技术方法来应对安全计算的挑战。可信执行环境(TES)和安全多方计算(MPC)都旨在使计算在两种意义上值得信任:它们确保计算的完整性,即正确性,并且它们为它们计算所基于的数据提供机密性。然而,这两种方法在安全模型和性能方面截然不同。TES依靠硬件的特性来保证其安全。它们提供高性能,在某些情况下接近本地CPU速度,但已被证明容易受到一些严重的旁路攻击。相反,MPC依赖于一个由合作节点组成的委员会,该委员会具有强大的加密安全保证,并提供诚实的法定人数。然而,它的性能不足以满足常规应用的需要。这个项目的新奇之处在于通过综合TES和MPC来提供对安全协议设计的一般探索,利用它们各自的优势和弱点。该项目的影响将包括设计可用于企业和政府使用敏感消费者数据的新协议,同时降低数据泄露或违反政策的风险。它还将促进基于TEE的计算的有用性,这已经是行业公认的需求。为TES和MPC的组合进行数学建模和设计原则性的、基于经验的协议设计带来了一系列技术研究挑战。该项目从一个新的协议框架--“骑士和骑士”(KN框架)开始,应用TEE来限制TEE危害的影响,并利用MPC来实现更强大的系统安全。该项目将探索快速检测和广泛通知TEE危害的技术,限制此类危害对依赖应用程序的影响,并在需要时实现MPC的故障转移。它还将探索TEE可以反过来加强和提高MPC部署的性能的方法。最后,该项目考虑如何通过经典的分片技术来扩展KN框架,并使用隐藏分片边界的新技术。该项目以调查人员在通用可组合性(UC)框架中的先前经验为基础,作为严格的安全建模的基础,此外还使用了名为CANDID的去中心化身份平台作为测试平台。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
As sensitive digital information proliferates and concerns grow about its improper use by enterprises and governments, two major technical approaches have arisen to address the challenges of secure computation. Trusted execution environments (TEEs) and secure multiparty computation (MPC) both aim to make computation trustworthy in two senses: They ensure the integrity, i.e., correctness, of the computation, and they provide confidentiality for the data over which they compute. The two approaches differ starkly, however, in their security models and performance. TEEs rely on the properties of hardware for their security assurance. They offer high performance, in some cases close to native CPU speeds, but have proven vulnerable to a number of serious side-channel attacks. Conversely, MPC relies on a committee of cooperating nodes, with strong cryptographic security guarantees given an honest quorum. Its performance, however, is inadequate for regular use with conventional applications. The novelty of this project is to provide a general exploration of secure protocol design through a synthesis of TEEs and MPC that takes advantage of their respective strengths and weaknesses. The impacts of this project will include the design of new protocols that can be used in corporate and government use of sensitive consumer data, while mitigating the risk of data breaches or policy violations. It will also advance the usefulness of TEE-based computing which has been an industry recognized need.Mathematically modelling and devising principled, empirically grounded protocol designs for a combination of TEEs and MPC poses a range of technical research challenges. This project starts from a new protocol framework, "Knights and Knaves" (KN framework), that applies TEEs so as to limit the impact of TEE compromise and leverage MPC to achieve stronger systemic security. This project will explore techniques for rapid detection and broad notification of TEE compromise, constraining the impact of such compromise in relying applications, and enabling failover where needed to MPC. It will also explore ways that TEEs can conversely harden and improve the performance of MPC deployments. Finally, the project considers ways to scale the KN framework through the classic technique of sharding, with new techniques for concealing shard boundaries. The project builds on investigators’ prior experience in the Universal Composability (UC) framework as a basis for rigorous security modeling, and additionally uses a decentralized identity platform called CanDID as a testbed.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
NSF-BSF: SaTC: CORE: Small: Blockchain Fairness
-
批准号:1933655
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2019
-
负责人:Ari Juels
-
依托单位:
SaTC: CORE: Medium: Proactive and Reactive Mechanisms for Safer Smart Contracts
-
批准号:1704615
-
项目类别:Continuing Grant
-
资助金额:$119.99万
-
财政年份:2017
-
负责人:Ari Juels
-
依托单位:
TTP: Medium: Democratizing Secure Password Management
-
批准号:1564102
-
项目类别:Standard Grant
-
资助金额:$119.77万
-
财政年份:2016
-
负责人:Ari Juels
-
依托单位:
TWC: Medium: Collaborative: Distribution-Sensitive Cryptography
-
批准号:1514163
-
项目类别:Standard Grant
-
资助金额:$79.96万
-
财政年份:2015
-
负责人:Ari Juels
-
依托单位:
国内基金
海外基金
登录
查看更多内容
Research on Quantum Field Theory without a Lagrangian Description
-
批准号:24ZR1403900
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:SATOSHI NAWATA
-
依托单位:
Cell Research
-
批准号:31224802
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2012
-
负责人:程磊
-
依托单位:
Cell Research
-
批准号:31024804
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2010
-
负责人:程磊
-
依托单位:
Cell Research (细胞研究)
-
批准号:30824808
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2008
-
负责人:张爱兰
-
依托单位:
Research on the Rapid Growth Mechanism of KDP Crystal
-
批准号:10774081
-
项目类别:面上项目
-
资助金额:45.0万元
-
批准年份:2007
-
负责人:滕冰
-
依托单位: