CAREER: Verifying Security and Privacy of Distributed Applications
CAREER: Verifying Security and Privacy of Distributed Applications
批准号:
2338317
负责人:
Joseph Tassarotti
金额:
$60.0万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2024
资助国家:
美国
项目状态:
未结题
起止时间:
2024-05-01 至 2029-04-30
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Developing secure software systems is challenging because even small bugs can undermine the security of a system. One approach to reduce the incidence of bugs in software is known as formal verification, in which a developer constructs a mathematical proof that the software follows an intended specification. Yet existing tools for formal verification cannot be applied to establish the security and privacy of many applications. The reason is that these applications combine three challenging features and requirements: (1) concurrency, in which multiple computer systems interact at once, (2) fault-tolerance, meaning that systems must handle failures and crashes, and (3) randomization, in which programs generate and use random data to achieve security properties. Existing tools for formal verification only support a subset of these features. The project's novelty is a new approach to formal verification of systems that combines all three of these features, thereby enabling the verification of security and privacy properties of important applications. The project's impacts are in improving the reliability and correctness of secure software systems. In addition, the primary investigator is developing new teaching materials on verification of security and privacy properties of randomized systems.The technical approach is based on a new method for reasoning about randomized systems called asynchronous couplings. This method allows one to prove that two randomized programs behave in equivalent ways, even when the two programs generate random samples at different times and locations. The primary investigator is developing a new logic for program verification that combines asynchronous couplings with recently developed techniques for reasoning about distributed, fault-tolerant systems based on concurrent separation logic. The resulting logic is extensible, in the sense that higher-level techniques for proving security and privacy properties can be encoded in the logic.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
EAGER: SHF: Verified Audit Layers for Safe Machine Learning
-
批准号:2318724
-
项目类别:Standard Grant
-
资助金额:$19.95万
-
财政年份:2023
-
负责人:Joseph Tassarotti
-
依托单位:
Collaborative Research: FMitF: Track I: The Phlox framework for verifying a high-performance distributed database
-
批准号:2319168
-
项目类别:Standard Grant
-
资助金额:$24.99万
-
财政年份:2023
-
负责人:Joseph Tassarotti
-
依托单位:
Collaborative Research: FMitF: Track I: Composable Verification of Crash-Safe Distributed Systems with Grove
-
批准号:2318722
-
项目类别:Standard Grant
-
资助金额:$25.0万
-
财政年份:2023
-
负责人:Joseph Tassarotti
-
依托单位:
Collaborative Research: FMitF: Track I: Composable Verification of Crash-Safe Distributed Systems with Grove
-
批准号:2123842
-
项目类别:Standard Grant
-
资助金额:$25.0万
-
财政年份:2021
-
负责人:Joseph Tassarotti
-
依托单位:
EAGER: SHF: Verified Audit Layers for Safe Machine Learning
-
批准号:2035314
-
项目类别:Standard Grant
-
资助金额:$19.95万
-
财政年份:2020
-
负责人:Joseph Tassarotti
-
依托单位:
海外基金