课题基金 / 基金详情

Holistic Design of Secure Systems on Capability Hardware (HD-Sec)

Holistic Design of Secure Systems on Capability Hardware (HD-Sec)
能力硬件上安全系统的整体设计(HD-Sec)
批准号:
EP/V000489/1
负责人:
Michael Butler
金额:
$131.27万
依托单位:
依托单位国家:
英国
项目类别:
Research Grant
财政年份:
2020
资助国家:
英国
项目状态:
未结题
起止时间:
2020 至 --

项目摘要

项目成果

Michael Butler的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
Cybersecurity threats are causing damage to business and wider society and, if left unchecked, these threats will continue to grow. Poorly designed software is a significant source of cyber security vulnerabilities. Current software development practice relies heavily on an iterative build-test-fix approach to software correctness and, while testing of software is essential, it is very time-consuming and usually incomplete. A further weakness of the iterative build-test-fix approach is that it often results in design faults being discovered long after they were introduced in the development lifecycle - making them very expensive to fix once discovered. Formal methods are a body of mathematically-based techniques for design and verification of software that are more rigorous and systematic than build-test-fix, leading to better software designs with reduced bugs and vulnerabilities. Our vision is the transformation of security system development from an error-prone, iterative build-test-fix approach to a correctness-by-construction (CxC) approach whereby formal methods guide the design of software in such a way that it satisfies its specification by construction. The impact of this will be to reduce overall development costs, while increasing trustworthiness, of security-critical systems. Systems are designed by humans and used by humans. Formal methods are challenging to use for many software developers we will developed tools that reduce barriers to their deployment. Our tools will support developers to engage with wider stakeholders to elicit and validate requirements. Many secure systems rely on assumptions about the behaviour of trusted and untrusted users but often these assumptions are not clearly understood or defined. Our research will incorporate formal constraints on user data and actions and vulnerabilities in data integrity resulting from user behaviour in modelling and verification. Even if software has been verified correct, it is likely to be running on hardware that is vulnerable to cyber-attack because of poor memory protection. Today's open connected computing platforms allow hardware vulnerabilities to be exploited at scale and capability hardware has been proposed as an approach to reducing hardware vulnerabilities. Capability hardware, such as the CHERI architecture, provides a range of memory protection features, to enforce secure data operations and avoid incorrect or malicious manipulations of data. When using formal methods, we develop software that enforces secure data operations and thus, in principle, additional hardware enforcement is not required. However, securely-developed software is still likely to be executing in a context in which other code may be accidently or maliciously violating data access disciplines which would undermine the securely-developed code. By using capability hardware, we get enforcement of secure data operations on other code, avoiding the need to worry about interference by code over which we have no control. Our project will incorporate capability hardware features in to the formal design approach by developing high level design abstractions that capture properties of data operations appropriate for designing and verifying at higher abstraction levels. Our research will be guided and validated by a range of security-critical industrial case studies with support from our industrial partners (Airbus, Arm, Altran, AWE, Galois, L3Harris, Northrop Grumman, Thales). Key outcomes of HD-Sec will be:. An integrated toolchain to support the CxC approach for design of security systems. Sound high-level abstractions that facilitate exploitation of capability hardware in software design. A functioning prototype application designed using our CxC tools and running on capability hardware
期刊论文(10)
专著(0)
科研奖励(0)
会议论文
Scenario Checker: An Event-B tool for validating abstract models
Scenario Checker:用于验证抽象模型的 Event-B 工具
DOI: --
发表时间: 2021
期刊:
影响因子: --
作者: [Snook C]
通讯作者: Snook C
Rigorous State-Based Methods - 9th International Conference, ABZ 2023, Nancy, France, May 30-June 2, 2023, Proceedings
严格的基于国家的方法 - 第九届国际会议,ABZ 2023,法国南锡,2023 年 5 月 30 日至 6 月 2 日,会议记录
DOI: 10.1007/978-3-031-33163-3_17
发表时间: 2023
期刊:
影响因子: --
作者: [Salehi Fathabadi A]
通讯作者: Salehi Fathabadi A
A lightweight approach to the concurrent use and integration of SysML and formal methods in systems design
一种在系统设计中同时使用和集成 SysML 和形式化方法的轻量级方法
DOI: 10.1145/3550356.3559577
发表时间: 2022
期刊:
影响因子: --
作者: [Thorburn R]
通讯作者: Thorburn R
DOI: 10.1007/978-3-031-26236-4_11
发表时间: 2023
期刊:
影响因子: --
作者: [Hoang T]
通讯作者: Hoang T
9
    The TRANSFORMATION Project: Transferring knowledge to transform project management practice
    • 批准号:
      ES/H000283/1
    • 项目类别:
      Research Grant
    • 资助金额:
      $12.71万
    • 财政年份:
      2009
    • 负责人:
      Michael Butler
    • 依托单位:
    Underlying Heuristic and Formal Structures of Probabilistic Thought
    • 批准号:
      7822271
    • 项目类别:
      Standard Grant
    • 资助金额:
      $7.5万
    • 财政年份:
      1978
    • 负责人:
      Michael Butler
    • 依托单位:
    A Multi-Disciplinary Course, Introduction to Children, As a Research Topic
    • 批准号:
      7703410
    • 项目类别:
      Standard Grant
    • 资助金额:
      $1.24万
    • 财政年份:
      1977
    • 负责人:
      Michael Butler
    • 依托单位:
    国内基金
    海外基金
    Applications of AI in Market Design
    • 批准号:
      --
    • 项目类别:
      外国青年学者研 究基金项目
    • 资助金额:
      --
    • 批准年份:
      2024
    • 负责人:
      Manshu Khanna
    • 依托单位:
    基于“Design-Build-Test”循环策略的新型紫色杆菌素组合生物合成研究
    • 批准号:
    • 项目类别:
      省市级项目
    • 资助金额:
      --
    • 批准年份:
      2021
    • 负责人:
    • 依托单位:
    在噪声和约束条件下的unitary design的理论研究
    • 批准号:
      12147123
    • 项目类别:
      专项基金项目
    • 资助金额:
      18万元
    • 批准年份:
      2021
    • 负责人:
      顾炎武
    • 依托单位: