SCorCH: Secure Code for Capability Hardware
SCorCH: Secure Code for Capability Hardware
批准号:
EP/V000497/1
负责人:
Giles Reger
金额:
$131.88万
依托单位:
依托单位国家:
英国
项目类别:
Research Grant
财政年份:
2020
资助国家:
英国
项目状态:
已结题
起止时间:
2020 至 --
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Computers and smart phones are now used in all areas of everyday life, from business to education to entertainment. From the individual to the national level, we have become reliant on software systems and risk substantial loss if these systems fail or have their security compromised. The only way to protect against this is to ensure that the software has no inherent weakness, and this requires that we use the power of mathematics to ensure that the software is both safe and secure.As software systems grow more complex the potential for failure grows. Traditional testing approaches become unscalable and give weaker assurances about the safety of software systems. Similarly, our software systems are increasingly subject to attacks from those who seek to exploit our dependence on technology for their own nefarious purposes. These so-called cyber attacks are becoming more elaborate, actively seeking to subvert existing methods of detection. Only by removing the underlying vulnerabilities we can truly protect ourselves. Therefore, to properly handle notions of safety and security we must focus on fundamental properties of software systems and reason about them generally.However, software systems are not isolated, they run on hardware alongside other software and the safety and security of any software is dependent on this context. Ideally, we have safety and security `all the way down' from semicolons to silicon. A recent effort, let by ARM and the University of Cambridge, has introduced a new model for safe and secure systems: Capability Hardware. The most significant set of security vulnerabilities stem from memory being accessed or manipulated by a process that should not be allowed to access or manipulate that memory. The idea behind Capability Hardware is to provide security guarantees at the hardware level with special so-called capabilities, a special kind of memory that knows who is allowed to do what with it. The result should be much more secure and robust software systems. However, now that we have more security at the hardware level, it is key that we ensure that this is correctly utilised at the software level.This project aims to transport the substantial advanced in software verification to the setting of this new capability hardware. In general, we will extend existing tools and create new tools able to reason about the safety and security of industrially relevant software systems running on Capability Hardware. There will be a significant focus on achieving high technological readiness, ensuring that when the international community is ready to embrace Capability Hardware there already exists a mature set of tools able to verify the safety and security of the software sitting on top of it.
期刊论文(10)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
The ksmt calculus is a d-complete decision procedure for non-linear constraints
ksmt 演算是非线性约束的 d 完全决策过程
DOI:
10.1016/j.tcs.2023.114125
发表时间:
2023
期刊:
Theoretical Computer Science
影响因子:
1.1
作者:
[Brauße F]
通讯作者:
Brauße F
Tools and Algorithms for the Construction and Analysis of Systems - 29th International Conference, TACAS 2023, Held as Part of the European Joint Conferences on Theory and Practice of Software, ETAPS 2023, Paris, France, April 22-27, 2023, Proceedings, Part II
系统构建和分析的工具和算法 - 第 29 届国际会议,TACAS 2023,作为欧洲软件理论与实践联合会议的一部分举行,ETAPS 2023,法国巴黎,2023 年 4 月 22-27 日,会议记录,部分
DOI:
10.1007/978-3-031-30820-8_33
发表时间:
2023
期刊:
影响因子:
--
作者:
[Aljaafari F]
通讯作者:
Aljaafari F
Intelligent Computer Mathematics - 15th International Conference, CICM 2022, Tbilisi, Georgia, September 19-23, 2022, Proceedings
智能计算机数学 - 第 15 届国际会议,CICM 2022,格鲁吉亚第比利斯,2022 年 9 月 19-23 日,会议记录
DOI:
10.1007/978-3-031-16681-5_14
发表时间:
2022
期刊:
影响因子:
--
作者:
[Bhayat A]
通讯作者:
Bhayat A
DOI:
10.1145/3626787
发表时间:
2023-12
期刊:
Proceedings of the ACM on Measurement and Analysis of Computing Systems
影响因子:
--
作者:
[Stella Bitchebe;Yves Kone;Pierre Olivier;Jalil Boukhobza;Yérom-David Bromberg;D. Hagimont;A. Tchana]
通讯作者:
Stella Bitchebe;Yves Kone;Pierre Olivier;Jalil Boukhobza;Yérom-David Bromberg;D. Hagimont;A. Tchana
DOI:
10.1109/secdev53368.2022.00020
发表时间:
2021-06
期刊:
2022 IEEE Secure Development Conference (SecDev)
影响因子:
--
作者:
[A. Bhayat;L. Cordeiro;Giles Reger;F. Shmarov;Konstantin Korovin;T. Melham;Kaled Alshamrany;Mustafa A. Mustafa-Mustafa-A.-Mustafa-144411037;Pierre Olivier]
通讯作者:
A. Bhayat;L. Cordeiro;Giles Reger;F. Shmarov;Konstantin Korovin;T. Melham;Kaled Alshamrany;Mustafa A. Mustafa-Mustafa-A.-Mustafa-144411037;Pierre Olivier
共 10 条
CAPS: Collaborative Architectures for Proof Search
-
批准号:EP/V000209/1
-
项目类别:Research Grant
-
资助金额:$32.06万
-
财政年份:2020
-
负责人:Giles Reger
-
依托单位:
海外基金