课题基金 / 基金详情

Data security through trusted execution and comprehensive analysis framework

Data security through trusted execution and comprehensive analysis framework
通过可信执行和全面分析框架实现数据安全
批准号:
RGPIN-2017-04797
负责人:
Mannan, Mohammad
金额:
$1.68万
依托单位:
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2018
资助国家:
加拿大
项目状态:
已结题
起止时间:
2018-01-01 至 2019-12-31

项目摘要

项目成果

Mannan, Mohammad的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
In this proposal, I primarily target two complementary long-term objectives. (1) I will develop next generation data security mechanisms by leveraging existing and new hardware-based trusted computing features (e.g., trusted execution modes of modern CPUs, and security primitives implemented in chipsets, firmware, dedicated security chips) in three environments: laptops and client-end PCs, servers, and mobile devices. (2) I will develop new systematic and comprehensive security analysis frameworks for improved characterization of security failures due to implementation bugs and design flaws in real-world, complex software systems. I will also use trusted computing technologies to address security issues uncovered by such analysis frameworks.******Trusted computing technologies are largely under-utilized in current security solutions. Although such techniques are not new, and several academic proposals also exist, I believe real-world adoption is low due to many proposals being too narrow, i.e., solving only part of a complex problem, and processing secure user input and output is difficult. I will design more complete solutions, and present several target problems that have not been explored yet, specifically, problems that are too expensive or cumbersome to solve only through cryptographic/systems means. On the other hand, mechanisms for security analysis are in many cases adhoc, i.e., applicable to a certain piece of software or vulnerability. My goal is to develop frameworks that will be reusable (i.e., used for different software systems), and frameworks that can provide clear directions to improve security for system designers and product developers. I believe such frameworks and software tools (which I will open-source) will help researchers and developers to evaluate their intended systems more frequently, and more systematically.******The long-term vision of this proposal will be materialized through several short-term, concrete projects. I will explore security-critical applications (apps) in multiple platforms (desktops, servers, and mobile devices), including: protecting data against ransomware attacks; securely deleting data for device repurposing, and mitigating theft/coercion; securing in-memory confidential data against memory-extraction attacks; analyzing TLS implementations, and measuring real-world TLS interception; analyzing evasive malware, and consumer/enterprise applications. The target problems are broad, affecting many high-impact practical systems, and difficult to solve with current approaches. Overall, the use of trusted computing in the design of verifiable solutions, and being able to validate real-world systems through comprehensive security frameworks will increase trust for everyday/enterprise users, and encourage researchers to leverage trusted computing and rigorous analysis techniques from this proposal.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Data security through trusted execution and comprehensive analysis framework
  • 批准号:
    RGPIN-2017-04797
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $2.04万
  • 财政年份:
    2022
  • 负责人:
    Mannan, Mohammad
  • 依托单位:
Data security through trusted execution and comprehensive analysis framework
  • 批准号:
    RGPIN-2017-04797
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $1.68万
  • 财政年份:
    2021
  • 负责人:
    Mannan, Mohammad
  • 依托单位:
Data security through trusted execution and comprehensive analysis framework
  • 批准号:
    RGPIN-2017-04797
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $1.68万
  • 财政年份:
    2020
  • 负责人:
    Mannan, Mohammad
  • 依托单位:
Data security through trusted execution and comprehensive analysis framework
  • 批准号:
    RGPIN-2017-04797
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $1.68万
  • 财政年份:
    2019
  • 负责人:
    Mannan, Mohammad
  • 依托单位:
国内基金
海外基金
黄淮海平原典型区域土壤盐渍化演变机制与发生风险防控对策研究
存储安全中介系统理论、仿真和实现技术研究
  • 批准号:
    61070154
  • 项目类别:
    面上项目
  • 资助金额:
    30.0万元
  • 批准年份:
    2010
  • 负责人:
    韩德志
  • 依托单位:
最优证券设计及完善中国资本市场的路径选择
  • 批准号:
    70873012
  • 项目类别:
    面上项目
  • 资助金额:
    27.0万元
  • 批准年份:
    2008
  • 负责人:
    彭龙
  • 依托单位: