CAREER: Foundations for IoT Cloud Security
CAREER: Foundations for IoT Cloud Security
批准号:
2145675
负责人:
Luyi Xing
金额:
$55.07万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2022
资助国家:
美国
项目状态:
未结题
起止时间:
2022-07-01 至 2027-06-30
中文摘要
物联网(IoT)云是现代物联网系统(智能家居、工业、智慧城市、零售和健康应用等)基础的关键支柱之一。较新的物联网设备正在利用托管的平台即服务(PaaS)和基础设施即服务(IaaS)物联网云服务(例如,AWS物联网核心,Azure物联网中心),这些服务将大部分安全责任和部署负担从设备制造商转移到公共云提供商。物联网云必须管理数以亿计的物联网设备和用户的信任,并为设备制造商提供可靠和可用的工具,以实现安全的物联网部署。在物联网云系统中,安全性受损或部署不当可能导致危险和致命的后果。拟议工作的成果将(1)建立定义物联网云安全领域的基础科学理论、安全原则和实践;(2)保护PaaS和IaaS物联网云,这些云是智能家居、健康、工业、智慧城市、零售和关键基础设施免遭网络攻击的基础。在这个项目中开发的技术和工具将被物联网开发人员、行业安全分析师、学术研究人员和广泛的学生(系统安全、形式化方法和工程)使用。物联网云系统对大规模分布式信任管理和对新兴物联网计算范式(如物联网互操作性)的安全支持的需求带来了特定的挑战,这阻碍了为通用系统设计的解决方案的直接应用。该项目将描述这些挑战,同时解决三个关键的、新颖的研究重点。第一个重点是形式化有关物联网互操作性新兴范例的威胁,以进行新的攻击,并形式化验证其在物联网云系统和协议中的安全性。第二个重点是探索和理解利用设备制造商错误配置云物联网策略的新兴网络攻击,并开发创新的形式化建模和验证方法,以提高策略规范和基于云的物联网部署的安全保障。第三个重点是在前两个重点的基础上,确定了威胁和挑战,并通过开发具有一系列创新技术的系统化物联网云安全框架,从根本上解决威胁,包括物联网互操作性协议的安全全新设计,新型设备内通道控制框架,以及物联网代理(物联网云的核心组件)的强化供应链。通过这些重点,该项目将产生新的基础理解和方法,以保护现代和下一代物联网云系统。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
The Internet of things (IoT) cloud is one of the key pillars of the foundation upon which modern IoT systems rest (Smart Home, Industrial, Smart City, Retail, and Health applications, etc.). Newer IoT devices are taking advantage of the managed Platform-as-a-Service (PaaS) and Infrastructure-as-a-Service (IaaS) IoT cloud services (e.g., AWS IoT Core, Azure IoT Hub), which offload much of the security responsibilities and deployment burden from device manufacturers to the public cloud providers. IoT clouds must manage trust for hundreds of millions of IoT devices and users, and provide device manufacturers reliable and usable tools for secure IoT deployments. In the IoT cloud systems, compromised security or improper deployments can cause hazardous and deadly consequences. The outcomes of the proposed work will (1) establish the foundational scientific theory, security principles, and practices that define the field of IoT cloud security and (2) protect PaaS and IaaS IoT clouds that underlie the wide array of Smart Home, Health, Industrial, Smart City, Retail, and critical infrastructure from cyberattacks. Techniques and tools to be developed in this project will be used by IoT developers, security analysts in industry, academic researchers, and a wide range of students (system security, formal methods, and engineering).IoT cloud systems have specific challenges imposed by their requirements of large-scale distributed trust management and secure support of emerging IoT computing paradigms such as IoT interoperability, which preclude direct application of solutions devised for general-purpose systems. The project will characterize these challenges while addressing three key, novel research thrusts. The first thrust is to formalize the threats concerning the emerging paradigms of IoT interoperability to conduct novel attacks, and formally verify their security in IoT cloud systems and protocols. The second thrust is to explore and understand emerging cyberattacks leveraging misconfiguration of cloud IoT policies by device manufacturers, and develop innovative formal modeling and verification approaches to elevate security assurance of policy specification and cloud-based IoT deployments. The third thrust is informed by the first two thrusts, which identify the threats and challenges, and is to fundamentally address the threats by developing a systematized IoT-cloud security framework with a set of innovative techniques, including secure clean-slate design of IoT interoperability protocols, a novel in-device channel control framework, and hardened supply chain for IoT brokers (a core component of IoT clouds). Through these thrusts, this project will produce new foundational understanding and methods to safeguard modern and the next generation of IoT cloud systems.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(3)
专著(0)
科研奖励(0)
会议论文
DOI:
10.1145/3548606.3560590
发表时间:
2022-11
期刊:
Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
作者:
[Xin'an Zhou;Jiale Guan;Luyi Xing;Zhiyun Qian]
通讯作者:
Xin'an Zhou;Jiale Guan;Luyi Xing;Zhiyun Qian
DOI:
10.1145/3460120.3484592
发表时间:
2021-11
期刊:
Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
作者:
[Yan Jia;Bin Yuan;Luyi Xing;Dongfang Zhao;Yifan Zhang;Xiaofeng Wang;Yijing Liu;Kaimin Zheng;Peyton Crnjak;Yuqing Zhang;Deqing Zou;Hai Jin]
通讯作者:
Yan Jia;Bin Yuan;Luyi Xing;Dongfang Zhao;Yifan Zhang;Xiaofeng Wang;Yijing Liu;Kaimin Zheng;Peyton Crnjak;Yuqing Zhang;Deqing Zou;Hai Jin
DOI:
10.1145/3548606.3560680
发表时间:
2022-11
期刊:
Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
作者:
[Ze Jin;Luyi Xing;Yiwei Fang;Yan Jia;Bin Yuan;Qixu Liu]
通讯作者:
Ze Jin;Luyi Xing;Yiwei Fang;Yan Jia;Bin Yuan;Qixu Liu
Collaborative Research: EAGER: Towards Safeguarding the Emerging Miniapp Paradigm in Mobile Super Apps
-
批准号:2330265
-
项目类别:Standard Grant
-
资助金额:$15.0万
-
财政年份:2023
-
负责人:Luyi Xing
-
依托单位:
FMitF: Track II: Usability, Scalability, and Deployment Improvement of VerioT
-
批准号:2124225
-
项目类别:Standard Grant
-
资助金额:$10.0万
-
财政年份:2021
-
负责人:Luyi Xing
-
依托单位:
海外基金