CAREER: Security and Privacy Foundations of Internet-Scale User-Centered Automation
职业:互联网规模以用户为中心的自动化的安全和隐私基础
基本信息
- 批准号:2144376
- 负责人:
- 金额:$ 54.53万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Continuing Grant
- 财政年份:2022
- 资助国家:美国
- 起止时间:2022-02-01 至 2023-02-28
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
This award is funded in whole or in part under the American Rescue Plan Act of 2021 (Public Law 117-2).The digital and physical resources of people, such as emails, health data, smart home, and city devices, are now accessible on the Internet. By bringing all these systems online and making them interoperable, system operators enable new functionality and drive efficiencies. The enabler of such useful interconnections is the Internet-scale automation system, whose hallmark is permitting non-programmers to create automations, thus democratizing the bridge between digital and physical resources. Unfortunately, these automation systems are not secure and do not guarantee user privacy— attackers can steal sensitive user data and manipulate resources, including physical ones, at large scale. This project pursues an integrated research and education approach to endow Internet-scale automation with the correct security and privacy foundations. The project’s novelty is leveraging the unique properties of Internet-scale automation to develop a framework for securing them that strikes different trade-offs in functionality, performance, security, and usability. The broader significance and importance of the project are empowering non-programmers to securely create automations that improve convenience, safety, and energy efficiency in a privacy-preserving fashion.To provide the correct security foundations, the project focuses on building least-privilege distributed computer systems. Specifically, the unique properties of Internet-scale automation allow the adaptation of techniques from the theory of language-based data minimization, computing on encrypted data and human-centered design. Contributions to applied cryptography and data minimization include system-level innovations to make practical use of garbled circuits and program dependency analyses. Contributions to human-centered design include empirical studies and data-driven interface designs to help users write better automation programs. Rather than finding the security architecture, the project develops a framework of security architectures that strikes different trade-off points in functionality, usability, security, privacy, and performance. The project also introduces an automation simulator that integrates research results and makes them available for experimentation to students at universities and K-12.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
该奖项全部或部分由2021年美国救援计划法案(公法117-2)资助。人们的数字和物理资源,如电子邮件,健康数据,智能家居和城市设备,现在可以在互联网上访问。通过将所有这些系统联机并使其具有互操作性,系统运营商可以实现新功能并提高效率。互联网规模的自动化系统是这种有用的互连的推动者,其标志是允许非程序员创建自动化,从而使数字和物理资源之间的桥梁民主化。不幸的是,这些自动化系统并不安全,也不能保证用户隐私--攻击者可以窃取敏感的用户数据,并大规模地操纵资源,包括物理资源。该项目采用综合研究和教育方法,为互联网规模的自动化提供正确的安全和隐私基础。该项目的新奇之处在于利用互联网规模自动化的独特属性来开发一个框架,以保护它们在功能,性能,安全性和可用性方面进行不同的权衡。该项目更广泛的意义和重要性是使非程序员能够安全地创建自动化,以保护隐私的方式提高便利性,安全性和能源效率。为了提供正确的安全基础,该项目专注于构建最低特权的分布式计算机系统。具体而言,互联网规模自动化的独特属性允许从基于语言的数据最小化理论,加密数据计算和以人为本的设计中调整技术。对应用密码学和数据最小化的贡献包括系统级创新,以实际使用乱码电路和程序依赖性分析。对以人为本的设计的贡献包括实证研究和数据驱动的界面设计,以帮助用户编写更好的自动化程序。该项目不是寻找安全架构,而是开发一个安全架构框架,在功能,可用性,安全性,隐私和性能方面进行不同的权衡。该项目还引入了一个自动化模拟器,该模拟器集成了研究结果,并将其提供给大学和K-12的学生进行实验。该奖项反映了NSF的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Earlence Fernandes其他文献
Applying the Opacified Computation Model to Enforce Information Flow Policies in IoT Applications
应用不透明计算模型在物联网应用中实施信息流策略
- DOI:
- 发表时间:
2016 - 期刊:
- 影响因子:0
- 作者:
Amir Rahmati;Earlence Fernandes;A. Prakash - 通讯作者:
A. Prakash
IFTTT vs. Zapier: A Comparative Study of Trigger-Action Programming Frameworks
IFTTT 与 Zapier:触发动作编程框架的比较研究
- DOI:
- 发表时间:
2017 - 期刊:
- 影响因子:0
- 作者:
Amir Rahmati;Earlence Fernandes;Jaeyeon Jung;A. Prakash - 通讯作者:
A. Prakash
Practical Data Access Minimization in Trigger-Action Platforms
触发操作平台中的实际数据访问最小化
- DOI:
- 发表时间:
2022 - 期刊:
- 影响因子:0
- 作者:
Yunang Chen;Mohannad J. Alhanahnah;A. Sabelfeld;Rahul Chatterjee;Earlence Fernandes - 通讯作者:
Earlence Fernandes
Decoupled-IFTTT: Constraining Privilege in Trigger-Action Platforms for the Internet of Things
解耦 IFTTT:限制物联网触发操作平台的权限
- DOI:
- 发表时间:
2017 - 期刊:
- 影响因子:0
- 作者:
Earlence Fernandes;Amir Rahmati;Jaeyeon Jung;A. Prakash - 通讯作者:
A. Prakash
MOSES: supporting operation modes on smartphones
MOSES:支持智能手机上的操作模式
- DOI:
- 发表时间:
2012 - 期刊:
- 影响因子:0
- 作者:
G. Russello;M. Conti;B. Crispo;Earlence Fernandes - 通讯作者:
Earlence Fernandes
Earlence Fernandes的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Earlence Fernandes', 18)}}的其他基金
CAREER: Security and Privacy Foundations of Internet-Scale User-Centered Automation
职业:互联网规模以用户为中心的自动化的安全和隐私基础
- 批准号:
2312119 - 财政年份:2022
- 资助金额:
$ 54.53万 - 项目类别:
Continuing Grant
相似海外基金
CAREER: Verifying Security and Privacy of Distributed Applications
职业:验证分布式应用程序的安全性和隐私
- 批准号:
2338317 - 财政年份:2024
- 资助金额:
$ 54.53万 - 项目类别:
Continuing Grant
GNNs for Network Security (and Privacy) GRAPHS4SEC
用于网络安全(和隐私)的 GNN GRAPHS4SEC
- 批准号:
EP/Y036050/1 - 财政年份:2024
- 资助金额:
$ 54.53万 - 项目类别:
Research Grant
Travel: NSF Student Travel Grant for 2024 IEEE Symposium on Security and Privacy (IEEE S&P 2024)
旅行:2024 年 IEEE 安全与隐私研讨会 (IEEE S
- 批准号:
2419095 - 财政年份:2024
- 资助金额:
$ 54.53万 - 项目类别:
Standard Grant
Travel: NSF Student Travel Grant for the Twentieth Symposium on Usable Privacy and Security (SOUPS 2024) and the 33rd USENIX Security Symposium (USENIX Security 2024)
旅行:为第二十届可用隐私和安全研讨会 (SOUPS 2024) 和第 33 届 USENIX 安全研讨会 (USENIX Security 2024) 提供 NSF 学生旅行补助金
- 批准号:
2415713 - 财政年份:2024
- 资助金额:
$ 54.53万 - 项目类别:
Standard Grant
Travel: NSF Student Travel Grant for 2024 ISOC Symposium on Vehicle Security and Privacy (VehicleSec)
旅行:2024 年 ISOC 车辆安全和隐私研讨会 (VehicleSec) 的 NSF 学生旅行补助金
- 批准号:
2419978 - 财政年份:2024
- 资助金额:
$ 54.53万 - 项目类别:
Standard Grant
SPRITE+ 2: The Security, Privacy, Identity and Trust Engagement Networkplus (phase 2).
SPRITE 2:安全、隐私、身份和信任参与网络plus(第2阶段)。
- 批准号:
EP/W020408/1 - 财政年份:2023
- 资助金额:
$ 54.53万 - 项目类别:
Research Grant
Education DCL: EAGER: Experiential Learning Platform and Curricular Modules for Quantum Computing Security and Privacy Education
教育 DCL:EAGER:量子计算安全和隐私教育的体验式学习平台和课程模块
- 批准号:
2335788 - 财政年份:2023
- 资助金额:
$ 54.53万 - 项目类别:
Standard Grant
CAREER: Privacy Preserving Security Analytics: When Security Meets Privacy
职业:隐私保护安全分析:当安全遇到隐私时
- 批准号:
2308730 - 财政年份:2023
- 资助金额:
$ 54.53万 - 项目类别:
Continuing Grant
SaTC-EDU: EAGER: Developing metaverse-native security and privacy curricula for high school students
SaTC-EDU:EAGER:为高中生开发元宇宙原生安全和隐私课程
- 批准号:
2335807 - 财政年份:2023
- 资助金额:
$ 54.53万 - 项目类别:
Standard Grant
Intelligent and Privacy-preserving security solutions for IoT networks
适用于物联网网络的智能且保护隐私的安全解决方案
- 批准号:
2890932 - 财政年份:2023
- 资助金额:
$ 54.53万 - 项目类别:
Studentship