CICI: UCSS: ScienceAccess: Enabling Zero-Trust Resource Access Management for Scientific Collaborations
CICI: UCSS: ScienceAccess: Enabling Zero-Trust Resource Access Management for Scientific Collaborations
批准号:
2232911
负责人:
Gail-Joon Ahn
金额:
$59.17万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2022
资助国家:
美国
项目状态:
未结题
起止时间:
2022-10-01 至 2025-09-30
中文摘要
科学协作通过允许共享各种资源,包括真实数据、高性能计算、网络通道等,极大地促进了科学的进步。由于这些资源的访问涉及多个利益相关者,因此基于一系列访问中介安全策略(AM策略)来规范资源共享活动至关重要,这些策略可满足各种机构、协作团队和研究人员的要求和约束。这种政策驱动的方法将有助于实现科学合作中的重要挑战:资源共享的公平性和处理数字资产的风险管理。然而,这样的AM策略是以一种特别的、半正式的和不完整的方式来指定、评估和实施的:(I)科学家仍然需要编写他们自己的AM策略,而他们在策略规范中没有表达能力,这使得他们很难正确地表达他们的特定需求。(2)在多个地方机构和管理人员之间评估和执行AM--政策的能力有限。(3)对系统地收集需要在运行时评估政策的与安全有关的数据的支持也有限。为了应对这些挑战,该项目开发了Science Access,这是一个支持AM策略的存储、检索、评估和实施的联合框架,允许科学家和管理员以高度自治的方式管理他们的资源共享需求。最终,Science Access试图产生以下结果:(I)阐明AM的新见解--有效地与包括亚利桑那州联邦开放研究计算飞地(AFORCE)和Science DMZ在内的现有网络基础设施共享资源和进行真实世界实验的政策;(Ii)有效地指定、评估和管理AM--具有零信任安全概念的AM-政策的新创新技术,包括以属性的形式在独立运行的科学机构之间自动收集和分发与安全相关的信息;以及(Iii)未来部署Science Access框架的评估、指导方针和最佳实践。该奖项反映了NSF的法定使命,并通过使用基金会的智力价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Scientific collaborations tremendously contribute to advancing science by allowing to share diverse resources including real data, high-performance computing, network channel, and so on. Since multiple stakeholders are involved in accessing those resources, it is critical to regulate resource sharing activities based on a series of access mediation security policies (AM-Policies) that fulfill requirements and constraints from various institutions, collaborative teams, and researchers. Such policy-driven approach would help achieve important challenges in scientific collaborations: fairness in resource sharing and risk management in dealing with digital assets. However, such AM-Policies have been specified, evaluated and enforced in an ad-hoc, semi-formal, and incomplete way: (i) scientists still need to write their own AM-Policies without having expressiveness power in policy specification, making it difficult for them to correctly articulate their specific needs. (ii) the evaluation and enforcement of AM-Policies across multiple local institutions and administrators are limited. (iii) there is also limited support for systematically collecting security-relevant data that needs to evaluate policies at run-time. To address these challenges, this project develops ScienceAccess, a federated framework supporting the storage, retrieval, evaluation, and enforcement of AM-Policies that allows for scientists and administrators to manage their resource sharing needs with a high degree of autonomy. Ultimately, ScienceAccess attempts to produce the following outcomes: (i) new insights to articulate AM-Policies for effectively sharing resources and real-world experiments with existing cyberinfrastructures including the Arizona Federated Open Research Computing Enclave (AFORCE) and Science DMZ; (ii) new innovative techniques to efficiently specify, evaluate, and manage AM-Policies with the notion of a Zero-Trust security, including the automated collection and distribution of security-relevant information in the form of attributes between independently-run scientific institutions; and (iii) assessments, guidelines, and best practices for future deployments of ScienceAccess framework.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(2)
专著(0)
科研奖励(0)
会议论文
DOI:
10.1109/dsn58367.2023.00035
发表时间:
2023-06
期刊:
2023 53rd Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN)
影响因子:
--
作者:
[Jaejong Baek;P. Soundrapandian;Sukwha Kyung;Ruoyu Wang;Yan Shoshitaishvili;Adam Doupé;Gail-Joon Ahn]
通讯作者:
Jaejong Baek;P. Soundrapandian;Sukwha Kyung;Ruoyu Wang;Yan Shoshitaishvili;Adam Doupé;Gail-Joon Ahn
SpaceMediator: Leveraging Authorization Policies to Prevent Spatial and Privacy Attacks in Mobile Augmented Reality
SpaceMediator:利用授权策略防止移动增强现实中的空间和隐私攻击
DOI:
10.1145/3589608.3593839
发表时间:
2023
期刊:
SACMAT '23: Proceedings of the 28th ACM Symposium on Access Control Models and Technologies
影响因子:
--
作者:
[Claramunt, Luis, Rubio-Medrano, Carlos, Baek, Jaejong, Ahn, Gail-Joon]
通讯作者:
Ahn, Gail-Joon
Collaborative Research: CICI: Secure and Resilient Architecture: SciGuard: Building a Security Architecture for Science DMZ Based on SDN and NFV Technologies
-
批准号:1642031
-
项目类别:Standard Grant
-
资助金额:$49.95万
-
财政年份:2017
-
负责人:Gail-Joon Ahn
-
依托单位:
NSF-SFS: Arizona Cyber Defense Scholarship
-
批准号:1663651
-
项目类别:Continuing Grant
-
资助金额:$399.78万
-
财政年份:2017
-
负责人:Gail-Joon Ahn
-
依托单位:
III: Small: Collaborative Research: Privacy-Aware Collaborative Data Sharing in Human-Centered Social Networks
-
批准号:1527268
-
项目类别:Standard Grant
-
资助金额:$20.0万
-
财政年份:2015
-
负责人:Gail-Joon Ahn
-
依托单位:
Support for the Educational Activities at ACM CCS 2014
-
批准号:1426109
-
项目类别:Standard Grant
-
资助金额:$2.0万
-
财政年份:2014
-
负责人:Gail-Joon Ahn
-
依托单位:
TC: Small: Collaborative Proposal: User-Controlled Persona in Virtual Community
-
批准号:0916688
-
项目类别:Continuing Grant
-
资助金额:$26.99万
-
财政年份:2009
-
负责人:Gail-Joon Ahn
-
依托单位:
CT-M: Collaborative Research: Securing Dynamic Online Social Networks
-
批准号:0831360
-
项目类别:Continuing Grant
-
资助金额:$50.0万
-
财政年份:2008
-
负责人:Gail-Joon Ahn
-
依托单位:
Collaborative Research: Secure Information Sharing in Internet-based Collaborative Applications
-
批准号:0900970
-
项目类别:Continuing Grant
-
资助金额:$6.17万
-
财政年份:2008
-
负责人:Gail-Joon Ahn
-
依托单位:
Collaborative Research: Secure Information Sharing in Internet-based Collaborative Applications
-
批准号:0242393
-
项目类别:Continuing Grant
-
资助金额:$13.0万
-
财政年份:2003
-
负责人:Gail-Joon Ahn
-
依托单位:
Exploratory Research-Scalable Token-Based Authentication: Architectures and Mechanisms
-
批准号:0124873
-
项目类别:Standard Grant
-
资助金额:$3.45万
-
财政年份:2001
-
负责人:Gail-Joon Ahn
-
依托单位:
海外基金