CAREER: Identifying, quantifying, and explaining design principles and user practices that enable effective long-term key management
职业:识别、量化和解释设计原则和用户实践,以实现有效的长期密钥管理
基本信息
- 批准号:2238001
- 负责人:
- 金额:$ 65.42万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Continuing Grant
- 财政年份:2023
- 资助国家:美国
- 起止时间:2023-05-01 至 2028-04-30
- 项目状态:未结题
- 来源:
- 关键词:
项目摘要
Many new security-related technologies have the potential to revolutionize individuals’ lives—for example, cryptocurrencies. However, the adoption of these technologies is stymied by their reliance on needing users to manage cryptographic keys (long strings of random characters). Prior research has shown users struggle to manage cryptographic keys, with existing key management systems often causing more problems than they solve. To improve the design of key management, this project investigates how key management is used in the real world. Data from these studies help identify which designs best promote utility, usability, and security, which designs fail to do so, and what new designs are needed. This project can improve our understanding of how to design key management systems that can be integrated with security-related technologies to increase their chance of being adopted. Results are being used to update and generate new curricula for university and K–12 students, helping educate and prepare the next generation of cybersecurity experts. The project will positively impact societal welfare and national defense.This project includes collecting quantitative and qualitative data about the utility, usability, and security of existing systems that rely on key management. Data are gathered from users who have successfully adopted key management systems, such as developers using end-to-end email encryption and novice users adopting a key management system for the first time. The studies examine general usage, how usage changes over time, how users manage multiple cryptographic keys, how they synchronize keys between devices, and how they recover access to lost keys. Methods include interviews, surveys, observational studies, and usability studies. Design principles identified throughout this research will be presented on a public-facing website that synthesizes this project’s results in a manner easily digested by cryptographic system vendors and other researchers.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
许多与安全相关的新技术有可能彻底改变个人的生活,例如加密货币。然而,这些技术的采用受到阻碍,因为它们依赖于需要用户管理加密密钥(长串随机字符)。先前的研究表明,用户很难管理加密密钥,现有的密钥管理系统往往造成比它们解决的问题更多的问题。为了改进密钥管理的设计,本项目研究了在现实世界中如何使用密钥管理。来自这些研究的数据有助于确定哪些设计最好地促进了实用性、可用性和安全性,哪些设计不能做到这一点,以及需要哪些新设计。这个项目可以提高我们对如何设计可以与安全相关技术集成的密钥管理系统的理解,以增加其被采用的机会。研究结果被用于更新和生成大学和K-12学生的新课程,帮助教育和培养下一代网络安全专家。该项目将对社会福利和国防产生积极影响。该项目包括收集关于依赖密钥管理的现有系统的效用、可用性和安全性的定量和定性数据。数据收集自已成功采用密钥管理系统的用户,例如使用端到端电子邮件加密的开发人员和首次采用密钥管理系统的新手用户。这些研究检查了一般用法、用法如何随时间变化、用户如何管理多个加密密钥、他们如何在设备之间同步密钥,以及他们如何恢复对丢失密钥的访问。方法包括访谈、调查、观察性研究和可用性研究。在整个研究过程中确定的设计原则将在一个面向公众的网站上展示,该网站以一种容易被加密系统供应商和其他研究人员消化的方式综合了这个项目的结果。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Scott Ruoti其他文献
DR AF T SoK : Blockchain Technology and Its Potential Use Cases
- DOI:
- 发表时间:
2019 - 期刊:
- 影响因子:0
- 作者:
Scott Ruoti - 通讯作者:
Scott Ruoti
The Emperor’s New Autofill Framework:A Security Analysis of Autofill on iOS and Android
皇帝的新自动填充框架:iOS和Android上自动填充的安全分析
- DOI:
10.1145/3485832.3485884 - 发表时间:
2021 - 期刊:
- 影响因子:0
- 作者:
Sean Oesch;Anuj Gautam;Scott Ruoti - 通讯作者:
Scott Ruoti
A Comparison of PGP, IBE, and Password-based Secure Email
- DOI:
- 发表时间:
2016 - 期刊:
- 影响因子:0
- 作者:
Scott Ruoti - 通讯作者:
Scott Ruoti
A Comparison of Three Approaches to Assist Users in Memorizing System-Assigned Passwords
帮助用户记住系统分配的密码的三种方法的比较
- DOI:
- 发表时间:
- 期刊:
- 影响因子:0
- 作者:
Michael Clark;Scott Ruoti;Michael Mendoza;Kenneth R. Seamons - 通讯作者:
Kenneth R. Seamons
Systematization of Password ManagerUse Cases and Design Paradigms
密码管理器用例和设计范式的系统化
- DOI:
- 发表时间:
2021 - 期刊:
- 影响因子:0
- 作者:
James Simmons;O. Diallo;Sean Oesch;Scott Ruoti - 通讯作者:
Scott Ruoti
Scott Ruoti的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Scott Ruoti', 18)}}的其他基金
SaTC: CORE: Small: Identifying and Quantifying Design Principles For Improving Password Manager Usage
SaTC:核心:小型:识别和量化改进密码管理器使用的设计原则
- 批准号:
2226404 - 财政年份:2022
- 资助金额:
$ 65.42万 - 项目类别:
Standard Grant
相似海外基金
Identifying and quantifying genetic effects on neurodevelopmental trajectories in adolescents
识别和量化遗传对青少年神经发育轨迹的影响
- 批准号:
10817321 - 财政年份:2023
- 资助金额:
$ 65.42万 - 项目类别:
SaTC: CORE: Small: Identifying and Quantifying Design Principles For Improving Password Manager Usage
SaTC:核心:小型:识别和量化改进密码管理器使用的设计原则
- 批准号:
2226404 - 财政年份:2022
- 资助金额:
$ 65.42万 - 项目类别:
Standard Grant
NSF Postdoctoral Fellowship in Biology FY 2020: Quantifying nutrient sharing across mutualisms and identifying involved genetic factors
2020 财年 NSF 生物学博士后奖学金:量化互利共生中的营养共享并识别相关遗传因素
- 批准号:
2109909 - 财政年份:2021
- 资助金额:
$ 65.42万 - 项目类别:
Fellowship Award
GEM: From the Micro to the Macro--Identifying the Mechanisms Responsible for Megaelectron-Volt (MeV) Electron Microbursts and Quantifying Their Role in Global Radiation Belt Losses
GEM:从微观到宏观——确定兆电子伏(MeV)电子微爆发的机制并量化其在全球辐射带损失中的作用
- 批准号:
2025706 - 财政年份:2020
- 资助金额:
$ 65.42万 - 项目类别:
Standard Grant
An optimized screening platform for identifying and quantifying biased agonists as drugs for the treatment of Opioid Use Disorder
用于识别和量化偏向激动剂作为阿片类药物使用障碍治疗药物的优化筛选平台
- 批准号:
10334560 - 财政年份:2019
- 资助金额:
$ 65.42万 - 项目类别:
An optimized screening platform for identifying and quantifying biased agonists as drugs for the treatment of Opioid Use Disorder
用于识别和量化偏向激动剂作为阿片类药物使用障碍治疗药物的优化筛选平台
- 批准号:
10303305 - 财政年份:2019
- 资助金额:
$ 65.42万 - 项目类别:
Identifying and quantifying metabolites of a novel Metarhizium robersil strain
新型绿僵菌 (Metarhizium robersil) 菌株代谢物的鉴定和定量
- 批准号:
548386-2019 - 财政年份:2019
- 资助金额:
$ 65.42万 - 项目类别:
Applied Research and Development Grants - Level 1
An optimized screening platform for identifying and quantifying biased agonists as drugs for the treatment of Opioid Use Disorder
用于识别和量化偏向激动剂作为阿片类药物使用障碍治疗药物的优化筛选平台
- 批准号:
9911512 - 财政年份:2019
- 资助金额:
$ 65.42万 - 项目类别:
FUTURE-STORMS: Quantifying uncertainties and identifying drivers of future changes in weather extremes from convection-permitting model ensembles
未来风暴:从允许对流的模型集合中量化不确定性并确定未来极端天气变化的驱动因素
- 批准号:
NE/R01079X/1 - 财政年份:2018
- 资助金额:
$ 65.42万 - 项目类别:
Research Grant
Collaborative Research: Refining and Testing Methods for Identifying and Quantifying Gaseous Oxidized Mercury in Air
合作研究:识别和量化空气中气态氧化汞的精炼和测试方法
- 批准号:
1700722 - 财政年份:2017
- 资助金额:
$ 65.42万 - 项目类别:
Standard Grant