课题基金 / 基金详情

SaTC: CORE: Medium: Provably Secure, Usable, and Performant Enclaves in Multicore Processors

SaTC: CORE: Medium: Provably Secure, Usable, and Performant Enclaves in Multicore Processors
SaTC:CORE:中:多核处理器中可证明安全、可用且高性能的 Enclave
批准号:
2115587
负责人:
Srini Devadas
金额:
$120.0万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2021
资助国家:
美国
项目状态:
已结题
起止时间:
2021-10-01 至 2024-09-30

项目摘要

项目成果

Srini Devadas的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
In cloud computing and other popular modes of computer usage today, one physical computer is shared by different applications contributed by users who do not trust each other. The resources of the shared computer must be divided securely across the users; mistakes allow one user to learn another's secrets or influence another applications’ execution. A promising approach to address the challenge of protecting applications from one another is enclaves, best known through Intel's SGX architecture available since 2015, but SGX allows secrets to be leaked while applications execute. This project develops enclaves with strong protections, focusing on usability, performance, and assurance. First, enclaves have still been used relatively rarely in production, and the project therefore studies new interfaces that streamline the sharing of hardware resources. Second, to motivate adoption by the community, the developed enclaves encompass hardware optimizations so as not to affect runtime performance of applications. Third, the project develops techniques for mathematical proofs of hardware security. Planned approaches in software API design for enclaves include limited I/O channel interfaces (e.g., enforcing fixed or otherwise relatively predictable schedules) and new flexible means of allocating resources like cache lines across enclaves. New enclave-to-enclave communication primitives are realized through modifications to memory-management hardware. These mechanisms are being proved secure to the highest standards of mathematical rigor, through machine-checking of proofs with the Coq theorem prover. The technique is to prove that specific enclave systems cycle-accurately simulate groups of separate computers (one per enclave) connected by a basic network, and to prove such results modularly, via nonobvious decomposition of proof obligations into localized security conditions for different components (e.g., processor vs. memory system). This research produces usable enclave systems that the investigators make available to the public as images for Amazon's F1 cloud-FPGA system, facilitating easy bring-up for security evaluation or extending the work.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(2)
专著(0)
科研奖励(0)
会议论文
SaTC: CORE: Medium: Collaborative: Hardening Off-the-Shelf Software Against Side Channel Attacks
SaTC: CORE: Small: Design of Efficient, Horizontally-Scaling, and Strongly Anonymous Communication Networks
SPX: Collaborative Research: Distributed Database Management with Logical Leases and Hardware Transactional Memory
STARSS: Small: Trapdoor Computational Fuzzy Extractors
国内基金
海外基金
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
  • 批准号:
    82371765
  • 项目类别:
    面上项目
  • 资助金额:
    50万元
  • 批准年份:
    2023
  • 负责人:
    谭广云
  • 依托单位:
锕系元素5f-in-core的GTH赝势和基组的开发
  • 批准号:
    22303037
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    30万元
  • 批准年份:
    2023
  • 负责人:
    鲁俊波
  • 依托单位:
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
  • 批准号:
    --
  • 项目类别:
    --
  • 资助金额:
    52万元
  • 批准年份:
    2022
  • 负责人:
    孙丙军
  • 依托单位:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
  • 批准号:
    --
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    30万元
  • 批准年份:
    2022
  • 负责人:
    叶成林
  • 依托单位: