CCRI:Planning-C:SCA-in-Cloud: Infrastructure to Perform Side-Channel Attacks on Cryptographic Algorithms
CCRI:Planning-C:SCA-in-Cloud: Infrastructure to Perform Side-Channel Attacks on Cryptographic Algorithms
批准号:
2213738
负责人:
Miaoqing Huang
金额:
$10.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2022
资助国家:
美国
项目状态:
已结题
起止时间:
2022-10-01 至 2024-09-30
中文摘要
该项目侧重于规划活动,从而开发远程可访问的研究基础设施,用于执行和分析对加密算法(云中的sca)的侧信道攻击。一旦投入使用,该基础设施将被设想为一个开放访问平台,供研究人员设计和评估在硬件和软件中实现的创新SCA方法(例如,定时、基于功率的)。这种开放基础设施的可用性还将鼓励更安全的开发实践,并为开发下一代加密算法的抗sca实现开辟新的基于社区的研究途径。这项计划拨款的一个关键目标是将不同的团体(密码学理论家、软件工程师、嵌入式和实时工程师以及网络安全从业者)合并成一个更可见的社区,并征求合作者和反馈,这是创建这个关键基础设施所必需的。在这个规划项目中有两个主要任务。第一个主要任务包括一系列外延活动,用于征求云中的sca基础设施的兴趣、需求和范围。外展策略包括在会议上进行调查和研讨会,以便与所有其他密码学活跃和有抱负的研究小组以及国家标准与技术研究所(NIST)进行直接互动和社区建设。此外,将成立一个咨询委员会,初步确定硬件/软件平台和基础设施中包含的已知侧信道攻击。第二个主要任务是开发基础设施的原型,其中将包括FPGA和嵌入式开发套件。该项目将始终将项目开发与本科生和研究生的研究和教育相结合,并使学生尽早了解安全、软件设计和硬件设计方面的最新进展。提议的基础设施将被阿肯色大学的嵌入式系统安全课程用于执行基于功率的侧信道攻击。我们将联系其他机构,以利用这种云中的sca基础设施。将鼓励女性和代表性不足的学生加入研究团队。此外,将在FPGA、HOST和Crypto等相关会议上组织教程和演示,向研究社区介绍基础设施。该网站https://sca-in-cloud.uark.edu专门用于基础设施的门户和所有数据、代码、结果和报告的项目存储库。所有用户将通过本网站访问基础设施,对加密算法进行侧信道攻击并获取结果。网站和所有项目文件将存储在由研究小组维护的台式计算机上3年。此外,GitHub项目将作为永久解决方案托管所有数据,代码结果和报告,并将从上述URL链接到。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
This project focuses on planning activities leading to the development of a remotely accessible research infrastructure for performing and analyzing side-channel attacks on cryptographic algorithms (SCA-in-Cloud). When commissioned, this infrastructure is envisioned serve as an open access platform for researchers to design and evaluate innovative SCA methods (e.g., timing, power-based) implemented in both hardware and software. The availability of this open infrastructure will also encourage more secure development practices and open new community-based research avenues to develop SCA-resistant implementations of next generation cryptographic algorithms. A key objective of this planning grant is to coalesce different groups (cryptography theorists, software engineers, embedded and real-time engineers, and cybersecurity practitioners) into a more visible community and solicit collaborators and feedback that is necessary to create this critical infrastructure.There are two major tasks in this planning project. The first major task includes a series of outreach activities for soliciting the interest, requirements, and the scope of the SCA-in-Cloud infrastructure. Outreach strategies include surveys and workshops at conferences for direct interactions and community building with all other cryptography active and aspirational research groups, and the National Institute of Standards and Technology (NIST). Further, an advisory committee will be formed for the initial determination of hardware/software platforms and known side-channel attacks included in the infrastructure. The second major task is to develop a prototype of the infrastructure, which will include FPGA and embedded development kits.This project will consistently integrate the project development with undergraduate and graduate research and education, and expose students early on to recent advances in security, software design, and hardware design. The proposed infrastructure will be used by the Embedded System Security course at the University of Arkansas for performing power-based side-channel attacks. Other institutions will be contacted to take advantage of this SCA-in-Cloud infrastructure. Women and underrepresented students will be encouraged to join the research team. Further, tutorials and demos will be organized at related conferences, such as FPGA, HOST, and Crypto for introducing the infrastructure to the research community.The website, https://sca-in-cloud.uark.edu, is dedicated to the portal to the infrastructure and the project repository for all data, code, results, and reports. All users will access the infrastructure through this website to perform side-channel attacks on cryptographic algorithms and obtain the results. The website and all project files will be stored on a desktop computer maintained by the research team for 3 years. In addition, a GitHub project will host all data, code results, and reports as a permanent solution, and will be linked to from the above URL.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(2)
专著(0)
科研奖励(0)
会议论文
Towards Cloud-based Infrastructure for Post-Quantum Cryptography Side-channel Attack Analysis
面向后量子密码学侧信道攻击分析的基于云的基础设施
DOI:
--
发表时间:
2023
期刊:
2023 IEEE Design Methodologies Conference
影响因子:
--
作者:
[Teague, Tristen, Mahzabin, Mayeesha, Nelson, Alexander, Andrews, David, Huang, Miaoqing]
通讯作者:
Huang, Miaoqing
DOI:
10.1145/3548606.3560673
发表时间:
2022-11
期刊:
Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
作者:
[Michael Fahr;Hunter Kippen;Andrew Kwong;T. Dang;Jacob Lichtinger;Dana Dachman-Soled;Daniel Genkin;Alexander Nelson;Ray A. Perlner;Arkady Yerukhimovich;Daniel Apon]
通讯作者:
Michael Fahr;Hunter Kippen;Andrew Kwong;T. Dang;Jacob Lichtinger;Dana Dachman-Soled;Daniel Genkin;Alexander Nelson;Ray A. Perlner;Arkady Yerukhimovich;Daniel Apon
Engaging Doctoral Students in Autonomic and Self-Organizing Computing Systems Research
-
批准号:2019541
-
项目类别:Standard Grant
-
资助金额:$0.75万
-
财政年份:2020
-
负责人:Miaoqing Huang
-
依托单位:
CSR: Small: Cache Design for Solid-State Drives and Its Application in Data-intensive Applications
-
批准号:1219062
-
项目类别:Standard Grant
-
资助金额:$23.0万
-
财政年份:2012
-
负责人:Miaoqing Huang
-
依托单位:
海外基金