SaTC: CORE: Small: Practice-Driven Cryptographic Theory
SaTC:核心:小型:实践驱动的密码理论
基本信息
- 批准号:2154272
- 负责人:
- 金额:$ 50万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2022
- 资助国家:美国
- 起止时间:2022-06-01 至 2025-05-31
- 项目状态:未结题
- 来源:
- 关键词:
项目摘要
When users go to a popular Internet site, their browser will show a lock symbol, indicating that cryptography is being used to secure the communications. This cryptography has different components, including signature schemes and schemes for authenticated encryption. The same cryptography is also the basis of security in popular messaging apps, and used in many cryptocurrencies. Similarly, Callisto, a tool that allows victims to report sexual assault while protecting their privacy, uses a new and advanced form of cryptography called a two-party secure computation protocol, and usage of this tool is expanding. But does all this cryptography actually work, meaning provide the expected security? This question is not moot: recent years have witnessed attacks breaking widely-deployed cryptography, and this impacts millions of people. This project aims to validate existing cryptography via mathematical proofs of security, an approach that is now well accepted as reducing the likelihood of failures. The work aims to provide such proofs for widely-used signature schemes, authenticated encryption schemes and two-party secure computation protocols, increasing security assurance for the cryptography in use today. The project will likewise identify forms of cryptography that are important to future capabilities and needs, and build this next-generation cryptography, accompanying it again by proof-based validation so as to reduce the risk of future failure. The broader impacts include a software tool called PlayCrypt that will educate students in the design of high-assurance cryptography as needed in industry today. The project will also seek to broaden participation by confronting paucity of women in academia as something to be addressed early in the pipeline, not later, and focus on identifying promising women undergraduates and, through research, advancing them to PhD positions; then, working with women PhD students, advancing them to faculty positions. EdDSA is a signature scheme that is a government standard and widely used on the Internet. Existing security proofs for it, however, suffer from three limitations: they fail to prove security of the scheme that is actually in use due to improper modeling of the hash functions; the reductions underlying the proofs are so loose that the quantitative security guarantee, for the 256-but curves in which the scheme is implemented, is almost nil; the quantitative security guarantees in the multi-user setting relevant to the Internet are even worse. This project aims to fill all these gaps, by introducing the filtered Random Oracle Model and a corresponding notion of filtered indifferentiability; and a reduction from the classical Schnorr signature scheme rather than from an algebraic problem. The project will also consider authenticated encryption schemes like Galois/Counter Mode (GCM) that are currently used to encrypt data over the Internet, and explain that they fail to provide security for certain choices of nonces, a gap to be filled with a framework that allows users to pick, with confidence, nonces we show, via proofs, to result in secure encryption. The project will also show how to extend current authenticated encryption schemes to ones that commit to their key, thereby preventing certain new classes of attacks on password-based encryption, and moreover show how key-committing authenticated encryption results in secure password-based authenticated encryption. Finally, the project will revisit the foundations of two-party secure computation, giving definitions amenable to a concrete-security treatment, and giving security proofs that deliver protocols whose security is quantitatively as high as possible, leading to the best possible efficiency for a desired level of security.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
当用户访问一个流行的互联网网站时,他们的浏览器将显示一个锁定符号,表明正在使用加密技术来保护通信。这种加密有不同的组成部分,包括签名方案和认证加密方案。同样的加密技术也是流行的消息应用程序的安全基础,并用于许多加密货币。类似地,Callisto是一种允许受害者在保护隐私的同时报告性侵犯的工具,它使用了一种新的高级密码学形式,称为双方安全计算协议,这种工具的使用正在扩大。但是,所有这些加密技术真的有效吗?也就是说提供了预期的安全性吗?这个问题并不是没有意义的:近年来,已经有攻击破坏了广泛部署的密码学,这影响了数百万人。该项目旨在通过安全性的数学证明来验证现有的密码学,这种方法现在被广泛接受为减少失败的可能性。该工作旨在为广泛使用的签名方案,认证加密方案和两方安全计算协议提供这样的证明,提高当今使用的密码学的安全性保证。该项目还将确定对未来能力和需求至关重要的加密形式,并构建这种下一代加密技术,同时再次进行基于证据的验证,以降低未来失败的风险。更广泛的影响包括一个名为PlayCrypt的软件工具,该工具将教育学生设计当今行业所需的高保证加密技术。该项目还将寻求扩大参与,将学术界中妇女人数不足的问题作为一个问题及早解决,而不是在以后解决,并将重点放在确定有前途的女本科生,通过研究,将她们提升到博士职位;然后,与女博士生合作,将她们提升到教师职位。EdDSA是一种签名方案,是政府标准,广泛用于互联网。现有的安全性证明存在三个局限性:由于对散列函数的建模不当,无法证明实际使用的方案的安全性;证明中的归约过于松散,以至于对256-but曲线的安全性保证几乎为零;在与因特网相关的多用户设置中的定量安全保证甚至更差。该项目旨在填补所有这些空白,通过引入过滤随机Oracle模型和过滤不可微性的相应概念;以及从经典Schnorr签名方案而不是从代数问题中减少。该项目还将考虑目前用于在互联网上加密数据的Galois/Counter Mode(GCM)等认证加密方案,并解释它们无法为某些随机数的选择提供安全性,这一空白将由一个框架填补,该框架允许用户有信心地选择我们通过证明显示的随机数,以实现安全加密。该项目还将展示如何将当前的认证加密方案扩展到提交其密钥的方案,从而防止对基于密码的加密的某些新类别的攻击,并展示密钥提交认证加密如何导致安全的基于密码的认证加密。最后,该项目将重新审视双方安全计算的基础,给出适合具体安全处理的定义,并给出安全证明,以提供安全性尽可能高的协议,该奖项反映了NSF的法定使命,并通过使用基金会的智力价值进行评估,被认为值得支持和更广泛的影响审查标准。
项目成果
期刊论文数量(4)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Hardening Signature Schemes via Derive-then-Derandomize: Stronger Security Proofs for EdDSA
通过 Derive-then-Derandomize 强化签名方案:EdDSA 的更强安全证明
- DOI:
- 发表时间:2023
- 期刊:
- 影响因子:0
- 作者:Bellare, Mihir;Davis, Hannah;Di, Zijing
- 通讯作者:Di, Zijing
When Messages Are Keys: Is HMAC a Dual-PRF?
当消息成为密钥时:HMAC 是双 PRF 吗?
- DOI:
- 发表时间:2023
- 期刊:
- 影响因子:0
- 作者:Backendal, Matilda;Bellare, Mihir;Günther, Felix;Scarlata, Matteo
- 通讯作者:Scarlata, Matteo
Flexible Password-Based Encryption: Securing Cloud Storage and Provably Resisting Partitioning-Oracle Attacks
灵活的基于密码的加密:保护云存储并可证明抵御分区 Oracle 攻击
- DOI:
- 发表时间:2023
- 期刊:
- 影响因子:0
- 作者:Bellare, Mihir;Shea, Laura
- 通讯作者:Shea, Laura
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Mihir Bellare其他文献
Symmetric and Dual PRFs from Standard Assumptions: A Generic Validation of a Prevailing Assumption
- DOI:
10.1007/s00145-024-09513-6 - 发表时间:
2024-08-19 - 期刊:
- 影响因子:2.200
- 作者:
Mihir Bellare;Anna Lysyanskaya - 通讯作者:
Anna Lysyanskaya
Systèmes et procédés pour distribuer et sécuriser des données
分销商和受赠者安全系统和程序
- DOI:
- 发表时间:
2007 - 期刊:
- 影响因子:0
- 作者:
Mihir Bellare;Phillip Rogaway - 通讯作者:
Phillip Rogaway
Mihir Bellare的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Mihir Bellare', 18)}}的其他基金
SaTC: CORE: Small: Foundations of Applied Cryptography
SaTC:核心:小:应用密码学的基础
- 批准号:
1717640 - 财政年份:2017
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
TWC: Small: Subversion-Resistant Cryptography
TWC:小型:抗颠覆密码学
- 批准号:
1526801 - 财政年份:2015
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
TWC: Medium: Collaborative: Deconstructing Encryption
TWC:媒介:协作:解构加密
- 批准号:
1228890 - 财政年份:2012
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
TC: Small: A Cryptographic Treatment of the Wiretap Channel
TC:小:窃听通道的加密处理
- 批准号:
1116800 - 财政年份:2011
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
TC:Small: Systems-Sensitive Cryptography
TC:Small:系统敏感密码学
- 批准号:
0915675 - 财政年份:2009
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
CT-ISG: Cryptography for Computational Grids
CT-ISG:计算网格密码学
- 批准号:
0627779 - 财政年份:2006
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
CT-ISG: Practice-Oriented Provable-Security for Emerging Cryptographic Applications
CT-ISG:新兴密码应用程序的面向实践的可证明安全性
- 批准号:
0524765 - 财政年份:2005
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
Cryptographic Mechanisms for Internet Security
互联网安全的加密机制
- 批准号:
0129617 - 财政年份:2002
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
Design and Analysis of Cryptographic Protocols for Secure Communication
安全通信密码协议的设计与分析
- 批准号:
0098123 - 财政年份:2001
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
Career: Cryptography, Proof Checking and Approximation
职业:密码学、证明检查和近似
- 批准号:
9624439 - 财政年份:1996
- 资助金额:
$ 50万 - 项目类别:
Continuing Grant
相似国自然基金
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
- 批准号:82371765
- 批准年份:2023
- 资助金额:50 万元
- 项目类别:面上项目
锕系元素5f-in-core的GTH赝势和基组的开发
- 批准号:22303037
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
- 批准号:
- 批准年份:2022
- 资助金额:52 万元
- 项目类别:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
- 批准号:
- 批准年份:2022
- 资助金额:30 万元
- 项目类别:青年科学基金项目
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
- 批准号:
- 批准年份:2020
- 资助金额:55 万元
- 项目类别:
肌营养不良蛋白聚糖Core M3型甘露糖肽的精确制备及功能探索
- 批准号:92053110
- 批准年份:2020
- 资助金额:70.0 万元
- 项目类别:重大研究计划
Core-1-O型聚糖黏蛋白缺陷诱导胃炎发生并介导慢性胃炎向胃癌转化的分子机制研究
- 批准号:81902805
- 批准年份:2019
- 资助金额:20.5 万元
- 项目类别:青年科学基金项目
原始地球增生晚期的Core-merging大碰撞事件:地核增生、核幔平衡与核幔边界结构的新认识
- 批准号:41973063
- 批准年份:2019
- 资助金额:65.0 万元
- 项目类别:面上项目
RBM38通过协助Pol-ε结合、招募core调控HBV复制
- 批准号:31900138
- 批准年份:2019
- 资助金额:24.0 万元
- 项目类别:青年科学基金项目
CORDEX-CORE区域气候模拟与预估研讨会
- 批准号:41981240365
- 批准年份:2019
- 资助金额:1.5 万元
- 项目类别:国际(地区)合作与交流项目
相似海外基金
SaTC: CORE: Small: An evaluation framework and methodology to streamline Hardware Performance Counters as the next-generation malware detection system
SaTC:核心:小型:简化硬件性能计数器作为下一代恶意软件检测系统的评估框架和方法
- 批准号:
2327427 - 财政年份:2024
- 资助金额:
$ 50万 - 项目类别:
Continuing Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
- 批准号:
2338301 - 财政年份:2024
- 资助金额:
$ 50万 - 项目类别:
Continuing Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
- 批准号:
2338302 - 财政年份:2024
- 资助金额:
$ 50万 - 项目类别:
Continuing Grant
SaTC: CORE: Small: NSF-DST: Understanding Network Structure and Communication for Supporting Information Authenticity
SaTC:核心:小型:NSF-DST:了解支持信息真实性的网络结构和通信
- 批准号:
2343387 - 财政年份:2024
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
NSF-NSERC: SaTC: CORE: Small: Managing Risks of AI-generated Code in the Software Supply Chain
NSF-NSERC:SaTC:核心:小型:管理软件供应链中人工智能生成代码的风险
- 批准号:
2341206 - 财政年份:2024
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: CORE: Small: Towards Secure and Trustworthy Tree Models
协作研究:SaTC:核心:小型:迈向安全可信的树模型
- 批准号:
2413046 - 财政年份:2024
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
SaTC: CORE: Small: Socio-Technical Approaches for Securing Cyber-Physical Systems from False Claim Attacks
SaTC:核心:小型:保护网络物理系统免受虚假声明攻击的社会技术方法
- 批准号:
2310470 - 财政年份:2023
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
SaTC: CORE: Small: Study, Detection and Containment of Influence Campaigns
SaTC:核心:小型:影响力活动的研究、检测和遏制
- 批准号:
2321649 - 财政年份:2023
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: CORE: Small: Investigation of Naming Space Hijacking Threat and Its Defense
协作研究:SaTC:核心:小型:命名空间劫持威胁及其防御的调查
- 批准号:
2317830 - 财政年份:2023
- 资助金额:
$ 50万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Small: Towards a Privacy-Preserving Framework for Research on Private, Encrypted Social Networks
协作研究:SaTC:核心:小型:针对私有加密社交网络研究的隐私保护框架
- 批准号:
2318843 - 财政年份:2023
- 资助金额:
$ 50万 - 项目类别:
Continuing Grant