Data security through trusted execution and comprehensive analysis framework

通过可信执行和全面分析框架实现数据安全

基本信息

  • 批准号:
    RGPIN-2017-04797
  • 负责人:
  • 金额:
    $ 1.68万
  • 依托单位:
  • 依托单位国家:
    加拿大
  • 项目类别:
    Discovery Grants Program - Individual
  • 财政年份:
    2019
  • 资助国家:
    加拿大
  • 起止时间:
    2019-01-01 至 2020-12-31
  • 项目状态:
    已结题

项目摘要

In this proposal, I primarily target two complementary long-term objectives. (1) I will develop next generation data security mechanisms by leveraging existing and new hardware-based trusted computing features (e.g., trusted execution modes of modern CPUs, and security primitives implemented in chipsets, firmware, dedicated security chips) in three environments: laptops and client-end PCs, servers, and mobile devices. (2) I will develop new systematic and comprehensive security analysis frameworks for improved characterization of security failures due to implementation bugs and design flaws in real-world, complex software systems. I will also use trusted computing technologies to address security issues uncovered by such analysis frameworks.******Trusted computing technologies are largely under-utilized in current security solutions. Although such techniques are not new, and several academic proposals also exist, I believe real-world adoption is low due to many proposals being too narrow, i.e., solving only part of a complex problem, and processing secure user input and output is difficult. I will design more complete solutions, and present several target problems that have not been explored yet, specifically, problems that are too expensive or cumbersome to solve only through cryptographic/systems means. On the other hand, mechanisms for security analysis are in many cases adhoc, i.e., applicable to a certain piece of software or vulnerability. My goal is to develop frameworks that will be reusable (i.e., used for different software systems), and frameworks that can provide clear directions to improve security for system designers and product developers. I believe such frameworks and software tools (which I will open-source) will help researchers and developers to evaluate their intended systems more frequently, and more systematically.******The long-term vision of this proposal will be materialized through several short-term, concrete projects. I will explore security-critical applications (apps) in multiple platforms (desktops, servers, and mobile devices), including: protecting data against ransomware attacks; securely deleting data for device repurposing, and mitigating theft/coercion; securing in-memory confidential data against memory-extraction attacks; analyzing TLS implementations, and measuring real-world TLS interception; analyzing evasive malware, and consumer/enterprise applications. The target problems are broad, affecting many high-impact practical systems, and difficult to solve with current approaches. Overall, the use of trusted computing in the design of verifiable solutions, and being able to validate real-world systems through comprehensive security frameworks will increase trust for everyday/enterprise users, and encourage researchers to leverage trusted computing and rigorous analysis techniques from this proposal.
在这个提案中,我主要针对两个互补的长期目标。 (1) 我将通过在笔记本电脑和客户端 PC、服务器和移动设备这三种环境中利用现有的和新的基于硬件的可信计算功能(例如,现代 CPU 的可信执行模式,以及在芯片组、固件、专用安全芯片中实现的安全原语)来开发下一代数据安全机制。 (2) 我将开发新的系统和全面的安全分析框架,以改进对由于现实世界复杂软件系统中的实现错误和设计缺陷而导致的安全故障的表征。我还将使用可信计算技术来解决此类分析框架发现的安全问题。******可信计算技术在当前的安全解决方案中很大程度上没有得到充分利用。尽管此类技术并不新鲜,并且也存在一些学术建议,但我认为由于许多建议过于狭窄,即仅解决复杂问题的一部分,并且处理安全的用户输入和输出很困难,因此现实世界的采用率很低。我将设计更完整的解决方案,并提出几个尚未探索的目标问题,特别是那些过于昂贵或繁琐而仅通过密码/系统手段解决的问题。另一方面,安全分析机制在许多情况下是临时的,即适用于特定的软件或漏洞。我的目标是开发可重用的框架(即用于不同的软件系统),以及可以为系统设计者和产品开发者提供明确的方向来提高安全性的框架。我相信这样的框架和软件工具(我将开源)将帮助研究人员和开发人员更频繁、更系统地评估他们的预期系统。******该提案的长期愿景将通过几个短期的具体项目来实现。我将探索多个平台(桌面、服务器和移动设备)中的安全关键型应用程序(应用程序),包括:保护数据免受勒索软件攻击;安全删除数据以供设备重新利用,并减少盗窃/胁迫;保护内存中的机密数据免受内存提取攻击;分析 TLS 实施并测量现实世界的 TLS 拦截;分析规避恶意软件和消费者/企业应用程序。目标问题很广泛,影响许多高影响力的实际系统,并且很难用当前的方法解决。总体而言,在可验证解决方案的设计中使用可信计算,并能够通过全面的安全框架验证现实世界的系统,将增加日常/企业用户的信任,并鼓励研究人员利用该提案中的可信计算和严格的分析技术。

项目成果

期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Mannan, Mohammad其他文献

Revisiting Defenses against Large-Scale Online Password Guessing Attacks

Mannan, Mohammad的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Mannan, Mohammad', 18)}}的其他基金

Data security through trusted execution and comprehensive analysis framework
通过可信执行和全面分析框架实现数据安全
  • 批准号:
    RGPIN-2017-04797
  • 财政年份:
    2022
  • 资助金额:
    $ 1.68万
  • 项目类别:
    Discovery Grants Program - Individual
Data security through trusted execution and comprehensive analysis framework
通过可信执行和全面分析框架实现数据安全
  • 批准号:
    RGPIN-2017-04797
  • 财政年份:
    2021
  • 资助金额:
    $ 1.68万
  • 项目类别:
    Discovery Grants Program - Individual
Data security through trusted execution and comprehensive analysis framework
通过可信执行和全面分析框架实现数据安全
  • 批准号:
    RGPIN-2017-04797
  • 财政年份:
    2020
  • 资助金额:
    $ 1.68万
  • 项目类别:
    Discovery Grants Program - Individual
Data security through trusted execution and comprehensive analysis framework
通过可信执行和全面分析框架实现数据安全
  • 批准号:
    RGPIN-2017-04797
  • 财政年份:
    2018
  • 资助金额:
    $ 1.68万
  • 项目类别:
    Discovery Grants Program - Individual
Data security through trusted execution and comprehensive analysis framework
通过可信执行和全面分析框架实现数据安全
  • 批准号:
    RGPIN-2017-04797
  • 财政年份:
    2017
  • 资助金额:
    $ 1.68万
  • 项目类别:
    Discovery Grants Program - Individual
Security and Privacy of High Impact Computer Applications
高影响力计算机应用程序的安全和隐私
  • 批准号:
    418648-2012
  • 财政年份:
    2016
  • 资助金额:
    $ 1.68万
  • 项目类别:
    Discovery Grants Program - Individual
Analysis of Linux Container-based Security Mechanisms
基于Linux容器的安全机制分析
  • 批准号:
    487286-2015
  • 财政年份:
    2015
  • 资助金额:
    $ 1.68万
  • 项目类别:
    Engage Grants Program
Security and Privacy of High Impact Computer Applications
高影响力计算机应用程序的安全和隐私
  • 批准号:
    418648-2012
  • 财政年份:
    2015
  • 资助金额:
    $ 1.68万
  • 项目类别:
    Discovery Grants Program - Individual
Security and Privacy of High Impact Computer Applications
高影响力计算机应用程序的安全和隐私
  • 批准号:
    418648-2012
  • 财政年份:
    2014
  • 资助金额:
    $ 1.68万
  • 项目类别:
    Discovery Grants Program - Individual
Security and Privacy of High Impact Computer Applications
高影响力计算机应用程序的安全和隐私
  • 批准号:
    418648-2012
  • 财政年份:
    2013
  • 资助金额:
    $ 1.68万
  • 项目类别:
    Discovery Grants Program - Individual

相似国自然基金

黄淮海平原典型区域土壤盐渍化演变机制与发生风险防控对策研究
  • 批准号:
    41171178
  • 批准年份:
    2011
  • 资助金额:
    65.0 万元
  • 项目类别:
    面上项目
存储安全中介系统理论、仿真和实现技术研究
  • 批准号:
    61070154
  • 批准年份:
    2010
  • 资助金额:
    30.0 万元
  • 项目类别:
    面上项目
最优证券设计及完善中国资本市场的路径选择
  • 批准号:
    70873012
  • 批准年份:
    2008
  • 资助金额:
    27.0 万元
  • 项目类别:
    面上项目

相似海外基金

Data security through trusted execution and comprehensive analysis framework
通过可信执行和全面分析框架实现数据安全
  • 批准号:
    RGPIN-2017-04797
  • 财政年份:
    2022
  • 资助金额:
    $ 1.68万
  • 项目类别:
    Discovery Grants Program - Individual
Engaging Young Black and Latino Students in Data Science Through Water Security
通过水安全让年轻的黑人和拉丁裔学生参与数据科学
  • 批准号:
    2048958
  • 财政年份:
    2021
  • 资助金额:
    $ 1.68万
  • 项目类别:
    Standard Grant
Data security through trusted execution and comprehensive analysis framework
通过可信执行和全面分析框架实现数据安全
  • 批准号:
    RGPIN-2017-04797
  • 财政年份:
    2021
  • 资助金额:
    $ 1.68万
  • 项目类别:
    Discovery Grants Program - Individual
Data security through trusted execution and comprehensive analysis framework
通过可信执行和全面分析框架实现数据安全
  • 批准号:
    RGPIN-2017-04797
  • 财政年份:
    2020
  • 资助金额:
    $ 1.68万
  • 项目类别:
    Discovery Grants Program - Individual
SCC-IRG Track 1: Reducing Barriers to Residential Energy Security through an Integrated Case-management, Data-driven, Community-based approach
SCC-IRG 第 1 轨道:通过综合案例管理、数据驱动、基于社区的方法减少住宅能源安全障碍
  • 批准号:
    1952038
  • 财政年份:
    2020
  • 资助金额:
    $ 1.68万
  • 项目类别:
    Standard Grant
SaTC: CORE: Medium: Collaborative: Enabling Long-Term Security and Privacy through Retrospective Data Management
SaTC:核心:媒介:协作:通过回顾性数据管理实现长期安全和隐私
  • 批准号:
    1801644
  • 财政年份:
    2018
  • 资助金额:
    $ 1.68万
  • 项目类别:
    Continuing Grant
SaTC: CORE: Medium: Collaborative: Enabling Long-Term Security and Privacy through Retrospective Data Management
SaTC:核心:媒介:协作:通过回顾性数据管理实现长期安全和隐私
  • 批准号:
    1801663
  • 财政年份:
    2018
  • 资助金额:
    $ 1.68万
  • 项目类别:
    Continuing Grant
Data security through trusted execution and comprehensive analysis framework
通过可信执行和全面分析框架实现数据安全
  • 批准号:
    RGPIN-2017-04797
  • 财政年份:
    2018
  • 资助金额:
    $ 1.68万
  • 项目类别:
    Discovery Grants Program - Individual
Data security through trusted execution and comprehensive analysis framework
通过可信执行和全面分析框架实现数据安全
  • 批准号:
    RGPIN-2017-04797
  • 财政年份:
    2017
  • 资助金额:
    $ 1.68万
  • 项目类别:
    Discovery Grants Program - Individual
Constructing Life Course and Intergenerational Data Through Census Data Linkages
通过普查数据链接构建生命历程和代际数据
  • 批准号:
    9276711
  • 财政年份:
    2016
  • 资助金额:
    $ 1.68万
  • 项目类别:
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了