EIR: A Unified Theoretical Framework for Zero Trust Architectures
EIR:零信任架构的统一理论框架
基本信息
- 批准号:2200622
- 负责人:
- 金额:$ 30万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2022
- 资助国家:美国
- 起止时间:2022-09-01 至 2025-08-31
- 项目状态:未结题
- 来源:
- 关键词:
项目摘要
Zero Trust, has generally been explained as a network in which capabilities and access among all of the participating systems are highly regulated or require a sufficiently high level of proof before permissions are granted for any period of time. As reassuring as these words are for many in this space, the implementation of such networks and architecture lags due to the lack of an rigorous ground truth for success. In other words, if you ask any number of people to show you how they ”implemented” their Zero Trust environment with the same initial specifications you will get at a minimum number of responses with varying levels of verifiable security. The multiple responses are not the problem in this case as much as the variability in the level of security due to the ill-posed question of trust in these systems. The failure to develop true resilience is strongly related to the lack of a unified theoretical framework born out of fundamental cybersecurity experiments and results. This work will first frame and identify the appropriate scale for the question of trust in the cybersecurity domain. The education and research goals of this project are designed to strongly support the engagement in the community.The proposed research task is to do the research and development of the mathematical rules and bounds, e.g., first-order logic, formal methods, etc. to accurately encapsulate all the requirements needed to achieve a “True Zero Trust” architecture for a networked environment. The second research challenge is to prototype, build, test and attack these “True Zero-Trust” networks and compare them to other standards. These research tasks require accurate, detailed, and reproducible testbed construction and validation paired with the architecture. They will use Amazon Web Services to design and test initial architectures across four phases. The third research challenge is to verify the “True Zero-Trust” architecture at scale during varied attack scenarios under high utilization stress. The fourth research challenge is to develop an “Equation of State” for these systems that provides a “Figure of Merit” when judging the security of these systems. This work is strongly aligned with the CISE directorate’s mission in particular the CCF program’s Foundations of Emerging Technology thrust and the SaTC program.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
零信任通常被解释为一种网络,其中所有参与系统之间的能力和访问都受到高度管制,或者在任何时间段内授予权限之前需要足够高的证明。尽管这些话对这个领域的许多人来说是令人放心的,但由于缺乏严格的成功基础,这种网络和架构的实施滞后。换句话说,如果你要求任何数量的人向你展示他们是如何“实现”他们的零信任环境的,你将得到最少数量的响应,这些响应具有不同的可验证安全级别。在这种情况下,多个响应不是问题,而是由于这些系统中的信任问题的不适定而导致的安全级别的可变性。未能发展真正的弹性与缺乏一个统一的理论框架密切相关,该框架诞生于基本的网络安全实验和结果。这项工作将首先为网络安全领域的信任问题制定和确定适当的规模。本项目的教育和研究目标旨在大力支持社区的参与。拟议的研究任务是研究和开发数学规则和界限,例如,一阶逻辑、形式化方法等,以准确地封装实现网络环境的“真正零信任”架构所需的所有需求。第二个研究挑战是对这些“真正的零信任”网络进行原型设计、构建、测试和攻击,并将其与其他标准进行比较。这些研究任务需要准确,详细,可重复的测试平台的建设和验证与架构配对。 他们将使用Amazon Web Services在四个阶段设计和测试初始架构。第三个研究挑战是在高利用率压力下的各种攻击场景中大规模验证“真正的零信任”架构。第四个研究挑战是为这些系统开发一个“状态方程”,在判断这些系统的安全性时提供一个“品质因数”。这项工作与CISE董事会的使命,特别是CCF计划的新兴技术基础和SaTC计划密切相关。该奖项反映了NSF的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Onyema Osuagwu其他文献
Onyema Osuagwu的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Onyema Osuagwu', 18)}}的其他基金
Collaborative Research: Track 4: Developing Equity-Minded Engineering Practitioners (DEEP)
合作研究:轨道 4:培养具有公平意识的工程从业者 (DEEP)
- 批准号:
2308532 - 财政年份:2023
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
相似海外基金
Development of Unified Experimental and Theoretical Approach to Predict Reactive Transport in Subsurface Porous Media
预测地下多孔介质反应输运的统一实验和理论方法的发展
- 批准号:
EP/L012227/1 - 财政年份:2014
- 资助金额:
$ 30万 - 项目类别:
Research Grant
Development of Unified Experimental and Theoretical Approach to Predict Reactive Transport in Subsurface Porous Media
预测地下多孔介质反应输运的统一实验和理论方法的发展
- 批准号:
EP/L012251/1 - 财政年份:2014
- 资助金额:
$ 30万 - 项目类别:
Research Grant
A theoretical study to construct a unified model for high mass binaries with very high energy Gamma-ray emissions.
为具有极高能量伽马射线发射的高质量双星构建统一模型的理论研究。
- 批准号:
23540271 - 财政年份:2011
- 资助金额:
$ 30万 - 项目类别:
Grant-in-Aid for Scientific Research (C)
A unified approach to a theoretical explanation of pragmatically licensed constructions
对实用许可结构进行理论解释的统一方法
- 批准号:
23820051 - 财政年份:2011
- 资助金额:
$ 30万 - 项目类别:
Grant-in-Aid for Research Activity Start-up
Theoretical study on an unified process of planetesimal formation and accumulation
星子形成与积累统一过程的理论研究
- 批准号:
22540242 - 财政年份:2010
- 资助金额:
$ 30万 - 项目类别:
Grant-in-Aid for Scientific Research (C)
Theoretical and Numerical Investigation of a Unified Astrophysical Rotating Black Hole Model for Active Galactic Nuclei, Microquasars, and Gamma-Ray Bursters
活动星系核、微类星体和伽马射线暴的统一天体物理旋转黑洞模型的理论和数值研究
- 批准号:
0909098 - 财政年份:2009
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
Bayesian Mixture Models: Unified Theoretical Frameworks and MCMC Methods
贝叶斯混合模型:统一的理论框架和 MCMC 方法
- 批准号:
0906734 - 财政年份:2009
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
WordGraph - Development of a unified graph-theoretical system for acquiring lexico-semantic phenomena
WordGraph - 开发用于获取词汇语义现象的统一图论系统
- 批准号:
42840215 - 财政年份:2007
- 资助金额:
$ 30万 - 项目类别:
Research Grants
A Theoretical and Empirical Study on the Unified and Relativized Notion of Phase in Generative Grammar
生成语法中相的统一和相对化概念的理论和实证研究
- 批准号:
19520436 - 财政年份:2007
- 资助金额:
$ 30万 - 项目类别:
Grant-in-Aid for Scientific Research (C)
Collaborative Research: A Unified Theoretical Approach to Community Coevolution
协作研究:社区共同进化的统一理论方法
- 批准号:
0540392 - 财政年份:2006
- 资助金额:
$ 30万 - 项目类别:
Continuing Grant