Secure online services for private user data

保护私人用户数据的安全在线服务

基本信息

  • 批准号:
    RGPIN-2014-04180
  • 负责人:
  • 金额:
    $ 1.82万
  • 依托单位:
  • 依托单位国家:
    加拿大
  • 项目类别:
    Discovery Grants Program - Individual
  • 财政年份:
    2020
  • 资助国家:
    加拿大
  • 起止时间:
    2020-01-01 至 2021-12-31
  • 项目状态:
    已结题

项目摘要

When users are required to, or opt to, disclose private/sensitive data to an organization or government entity for processing, a balance must be struck between security and convenience. Online submission is often the most convenient but it also carries substantial risks. This research program proposes the development and deployment of innovative cryptographic protocols for providing secure online election systems and secure online genetic testing. Any security-critical online service must at least provide users with a process for determining they are connected to the intended party (server authentication) and then provide a confidential communication channel. These properties are intended when a user visits a website beginning with https:// (and the browser displays a lock), however, the trust assumptions and infrastructure this protocol (called SSL/TLS) relies on have been recently questioned. The research program will proceed in three thrusts: one toward improving the SSL/TLS infrastructure, one toward advancing beyond basic SSL/TLS protection for the specific application of online voting, and one that does the same for online genetic tests. When users visit a website over https://, the site provides a certificate of their identity, endorsed by a business or organization called a Certificate Authority (CA). Any CA can issue a certificate for any site. The number of CAs has proliferated, the baseline criteria for validation has declined, and high profile breeches of CAs have been publicly disclosed. This research program will design, implement, and test alternative mechanisms for certification. Online voting has been used municipally across Canada, is to be piloted federally by Elections Canada, and is being deliberated on by some provinces. Unlike online banking, where an incorrect, mistaken, or fraudulent transaction can be seen by the user, ballot secrecy mandates that individual votes cannot be displayed (which would enable vote selling). This research program will design, implement and test novel end-to-end verifiable (E2E) voting systems that provide a provably correct tally while maintaining the secrecy of each voter's ballot, even if the voter is complicit in demonstrating how they voted or uses a malware-infected personal computer to cast their ballot. The decreasing cost of whole genome sequencing has the potential to revolutionize healthcare, allowing genetic tests and personalized medicine. However, your genome is private information. Once it is disclosed or leaked, the privacy can never be recovered. This research program will design, implement and test novel cryptographic protocols for allowing these tests to be performed on an encrypted genome, while offering proof that the test was performed correctly (even if some aspects of the test remain confidential). The results of this research program should be informative and useful to government election agencies, privacy commissioners, standards institutes, internet working groups, other cryptography, security and privacy researchers, and to the elections and healthcare industry. It will further equip a set of security professionals with the skills required to work or consult in any of these areas, and to apply their knowledge and experience to novel domains.
当用户被要求或选择向组织或政府实体披露私人/敏感数据以供处理时,必须在安全性和便利性之间取得平衡。在线提交往往是最方便的,但它也带有很大的风险。这项研究计划建议开发和部署创新的密码协议,以提供安全的在线选举系统和安全的在线基因测试。任何安全关键型在线服务都必须至少为用户提供确定他们是否连接到目标方的流程(服务器身份验证),然后提供保密的通信通道。这些属性适用于用户访问以https://开头的网站(并且浏览器显示一个锁),但是,此协议(称为SSL/TLS)所依赖的信任假设和基础结构最近受到了质疑。 该研究计划将分三个阶段进行:一个是改善SSL/TLS基础设施,一个是超越针对在线投票特定应用的基本SSL/TLS保护,还有一个是为在线基因测试做同样的事情。 当用户通过https://,访问网站时,该网站提供他们的身份证书,该证书由称为证书颁发机构(CA)的企业或组织认可。任何CA都可以为任何站点颁发证书。CA的数量激增,验证的基线标准下降,CA的高调马裤已公开披露。这项研究计划将设计、实施和测试认证的替代机制。 在线投票已经在加拿大各地的市政当局使用,加拿大选举公司将在联邦范围内进行试点,一些省份正在考虑这一做法。与网上银行不同,在网上银行,用户可能会看到不正确、错误或欺诈性的交易,而投票保密规定不能显示个人选票(这将允许出售选票)。这项研究计划将设计、实施和测试新颖的端到端可验证(E2E)投票系统,该系统在提供可证明正确的计票结果的同时,保持每个选民的选票的保密性,即使选民是同谋展示他们如何投票或使用感染恶意软件的个人计算机投票。 全基因组测序成本的下降有可能给医疗保健带来革命性的变化,使基因测试和个性化医疗成为可能。然而,你的基因组是私人信息。一旦被披露或泄露,隐私将永远无法恢复。这项研究计划将设计、实施和测试新的密码协议,允许在加密的基因组上进行这些测试,同时提供测试正确执行的证据(即使测试的某些方面是保密的)。 这一研究项目的结果应该对政府选举机构、隐私专员、标准研究所、互联网工作组、其他密码学、安全和隐私研究人员以及选举和医疗保健行业具有参考价值。它将进一步使一批安全专业人员具备在任何这些领域工作或咨询所需的技能,并将他们的知识和经验应用于新的领域。

项目成果

期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Clark, Jeremy其他文献

Combining Molecular Subtypes with Multivariable Clinical Models Has the Potential to Improve Prediction of Treatment Outcomes in Prostate Cancer at Diagnosis.
  • DOI:
    10.3390/curroncol30010013
  • 发表时间:
    2022-12-22
  • 期刊:
  • 影响因子:
    2.6
  • 作者:
    Wardale, Lewis;Cardenas, Ryan;Gnanapragasam, Vincent J. J.;Cooper, Colin S. S.;Clark, Jeremy;Brewer, Daniel S. S.
  • 通讯作者:
    Brewer, Daniel S. S.
House Money Effects in Public Good Experiments
  • DOI:
    10.1023/a:1020832203804
  • 发表时间:
    2002-12-01
  • 期刊:
  • 影响因子:
    2.3
  • 作者:
    Clark, Jeremy
  • 通讯作者:
    Clark, Jeremy
Pepal: Penalizing multimedia breaches and partial leakages
Pepal:惩罚多媒体泄露和部分泄露
Systematic use of the serum C-reactive protein concentration and computed tomography for the detection of intestinal anastomotic leaks
  • DOI:
    10.1111/ans.15568
  • 发表时间:
    2020-01-01
  • 期刊:
  • 影响因子:
    1.7
  • 作者:
    Ho, Yiu Ming;Laycock, Juliet;Clark, Jeremy
  • 通讯作者:
    Clark, Jeremy
Evaluating the Effectiveness of School Funding and Targeting Different Measures of Student Disadvantage: Evidence from New Zealand
  • DOI:
    10.1111/1475-4932.12354
  • 发表时间:
    2017-12-01
  • 期刊:
  • 影响因子:
    1.2
  • 作者:
    Clark, Jeremy;Das, Susmita Roy;Menclova, Andrea
  • 通讯作者:
    Menclova, Andrea

Clark, Jeremy的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Clark, Jeremy', 18)}}的其他基金

Enhancing transparency, inclusion, and privacy for financial and democratic technologies
增强金融和民主技术的透明度、包容性和隐私
  • 批准号:
    RGPIN-2021-04019
  • 财政年份:
    2022
  • 资助金额:
    $ 1.82万
  • 项目类别:
    Discovery Grants Program - Individual
NSERC/RCGT/Catallaxy Industrial Research Chair in blockchain technologies
NSERC/RCGT/Catalaxy 区块链技术工业研究主席
  • 批准号:
    545498-2018
  • 财政年份:
    2021
  • 资助金额:
    $ 1.82万
  • 项目类别:
    Industrial Research Chairs
Enhancing transparency, inclusion, and privacy for financial and democratic technologies
增强金融和民主技术的透明度、包容性和隐私
  • 批准号:
    RGPIN-2021-04019
  • 财政年份:
    2021
  • 资助金额:
    $ 1.82万
  • 项目类别:
    Discovery Grants Program - Individual
NSERC/RCGT/Catallaxy Industrial Research Chair in blockchain technologies
NSERC/RCGT/Catalaxy 区块链技术工业研究主席
  • 批准号:
    545498-2018
  • 财政年份:
    2020
  • 资助金额:
    $ 1.82万
  • 项目类别:
    Industrial Research Chairs
NSERC/RCGT/Catallaxy Industrial Research Chair in blockchain technologies
NSERC/RCGT/Catalaxy 区块链技术工业研究主席
  • 批准号:
    545498-2018
  • 财政年份:
    2019
  • 资助金额:
    $ 1.82万
  • 项目类别:
    Industrial Research Chairs
Secure online services for private user data
保护私人用户数据的安全在线服务
  • 批准号:
    RGPIN-2014-04180
  • 财政年份:
    2017
  • 资助金额:
    $ 1.82万
  • 项目类别:
    Discovery Grants Program - Individual
Secure online services for private user data
保护私人用户数据的安全在线服务
  • 批准号:
    RGPIN-2014-04180
  • 财政年份:
    2016
  • 资助金额:
    $ 1.82万
  • 项目类别:
    Discovery Grants Program - Individual
Secure online services for private user data
保护私人用户数据的安全在线服务
  • 批准号:
    RGPIN-2014-04180
  • 财政年份:
    2015
  • 资助金额:
    $ 1.82万
  • 项目类别:
    Discovery Grants Program - Individual
Secure online services for private user data
保护私人用户数据的安全在线服务
  • 批准号:
    RGPIN-2014-04180
  • 财政年份:
    2014
  • 资助金额:
    $ 1.82万
  • 项目类别:
    Discovery Grants Program - Individual
Applied cryptography: internet voting and usability
应用密码学:互联网投票和可用性
  • 批准号:
    405005-2011
  • 财政年份:
    2012
  • 资助金额:
    $ 1.82万
  • 项目类别:
    Postdoctoral Fellowships

相似国自然基金

Scalable Learning and Optimization: High-dimensional Models and Online Decision-Making Strategies for Big Data Analysis
  • 批准号:
  • 批准年份:
    2024
  • 资助金额:
    万元
  • 项目类别:
    合作创新研究团队
Data-driven Recommendation System Construction of an Online Medical Platform Based on the Fusion of Information
  • 批准号:
  • 批准年份:
    2024
  • 资助金额:
    万元
  • 项目类别:
    外国青年学者研究基金项目
online SPE/HPLC-ICP-MS多元素形态分析新方法研究荷塘中铬砷镉汞铅的迁移转化规律
  • 批准号:
    21976048
  • 批准年份:
    2019
  • 资助金额:
    65.0 万元
  • 项目类别:
    面上项目
双积分政策下基于Online Review的新能源汽车企业跨链决策优化研究
  • 批准号:
    71964023
  • 批准年份:
    2019
  • 资助金额:
    27.5 万元
  • 项目类别:
    地区科学基金项目
面向Online-to-Offline智能商务的大数据融合与应用
  • 批准号:
    91646204
  • 批准年份:
    2016
  • 资助金额:
    201.0 万元
  • 项目类别:
    重大研究计划
基于个体分析的投影式非线性非负张量分解在高维非结构化数据模式分析中的研究
  • 批准号:
    61502059
  • 批准年份:
    2015
  • 资助金额:
    19.0 万元
  • 项目类别:
    青年科学基金项目
Online-to-Offline商务环境下"切客"一族生活模式挖掘研究
  • 批准号:
    71172046
  • 批准年份:
    2011
  • 资助金额:
    41.0 万元
  • 项目类别:
    面上项目
学习理论中基于核函数的正则化算法的研究
  • 批准号:
    11071276
  • 批准年份:
    2010
  • 资助金额:
    28.0 万元
  • 项目类别:
    面上项目

相似海外基金

HealthyU-Latinx: A Technology-based Tool for addressing Health Literacy in Latinx Secondary Students and their Families
HealthyU-Latinx:一种基于技术的工具,用于提高拉丁裔中学生及其家庭的健康素养
  • 批准号:
    10699830
  • 财政年份:
    2023
  • 资助金额:
    $ 1.82万
  • 项目类别:
Research and Methods Core-002
研究和方法 Core-002
  • 批准号:
    10660382
  • 财政年份:
    2023
  • 资助金额:
    $ 1.82万
  • 项目类别:
Biobehavioral Intervention to Reduce PTSD Symptoms After an ICD Shock
生物行为干预可减少 ICD 电击后的 PTSD 症状
  • 批准号:
    10722157
  • 财政年份:
    2023
  • 资助金额:
    $ 1.82万
  • 项目类别:
The IDeA State Consortium for a Clinical Research Resource Center: Increasing Clinical Trials in IDeA States through Communication of Opportunities, Effective Marketing, and WorkforceDevelopment
IDeA 州临床研究资源中心联盟:通过机会交流、有效营销和劳动力发展增加 IDeA 州的临床试验
  • 批准号:
    10715568
  • 财政年份:
    2023
  • 资助金额:
    $ 1.82万
  • 项目类别:
A Stage 1 Pilot Test for Feasibility and Efficacy of a Multi-Level Intervention To Increase Physical Activity in Adults with Intellectual Disability: Step it Up +
第一阶段试点测试多层次干预措施的可行性和有效性,以增加智力障碍成人的体力活动:加快步伐
  • 批准号:
    10585633
  • 财政年份:
    2023
  • 资助金额:
    $ 1.82万
  • 项目类别:
Analytical Core
分析核心
  • 批准号:
    10730061
  • 财政年份:
    2023
  • 资助金额:
    $ 1.82万
  • 项目类别:
Chromosomal aberration detection in FFPE tissue using proximity ligation sequencing
使用邻近连接测序检测 FFPE 组织中的染色体畸变
  • 批准号:
    10759887
  • 财政年份:
    2023
  • 资助金额:
    $ 1.82万
  • 项目类别:
Data Management Core
数据管理核心
  • 批准号:
    10682165
  • 财政年份:
    2023
  • 资助金额:
    $ 1.82万
  • 项目类别:
Toward measures and behavioral trials for effective online AUD recovery support
采取措施和行为试验以提供有效的在线澳元复苏支持
  • 批准号:
    10643056
  • 财政年份:
    2023
  • 资助金额:
    $ 1.82万
  • 项目类别:
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了