ITR: New Directions in Software Security
ITR: New Directions in Software Security
批准号:
0312809
负责人:
Amit Sahai
金额:
$40.0万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2003
资助国家:
美国
项目状态:
已结题
起止时间:
2003-08-15 至 2005-02-28
中文摘要
摘要:提案CCR-ITR 0312809 ITR:软件安全的新方向Amit Sahai人们普遍认为,当今计算机安全的最大威胁不是密码弱点,而是有缺陷的软件设计和实现,以及软件和硬件中保护信息的弱点。 这项研究提出了开发软件安全领域-通过全自动软件和硬件转换保护功能对象免受漏洞的影响。本研究提出的方法试图为这一领域建立一个新颖的理论基础。首先,本研究考虑了软件转换的广泛领域,以抵消软件缺陷(“错误”)造成的安全漏洞。 特别是,该项目将开发理论基础和工具,以防止利用漏洞控制远程系统的攻击。 更一般地说,这项研究的目的是分类的安全性,计算有限的软件转换可以提供。第二,这项研究考虑的问题,软件和硬件的隐私-如何确保对手不能学习重要的秘密,通过检查软件或硬件。 在这种情况下,本研究将研究转换,使得当攻击者获得对转换后的软件或硬件的访问权时,它无法了解嵌入在原始软件或硬件中的特定秘密,例如加密密钥或甚至可能是秘密算法技术。本研究将在各种假设下提出硬件和软件的此类转换,并试图确定何时不可能进行此类保护。
英文摘要
ABSTRACT:Proposal CCR-ITR 0312809 ITR: New Directions in Software SecurityAmit SahaiIt is widely believed that the greatest threat to computer security today is not cryptographic weakness but rather flawed software design and implementation, and weakness in protecting information within software and hardware. This research proposes to develop the area of software security - protecting functional objects from vulnerabilities by means of fully automated software and hardware transformations. The approaches proposed in this research attempt to build a novel and theoretically sound foundation to this field.First, this research considers the broad area of software transformations to counteract security vulnerabilities caused by flaws ("bugs") in software. In particular, this project will develop theoretical foundations and tools for preventing attacks which exploit flaws to gain control of remote systems. More generally, this research will aim to classify the security that computationally limited software transformations can provide.Second, this research considers the question of software and hardware privacy -- how to ensure that an adversary cannot learn important secrets by examining software or hardware. In this case, this research will study transformations such that, when the attacker gains access to the transformed software or hardware, it cannot learn specific secrets embedded in the original software or hardware, such as cryptographic keys or potentially even secret algorithmic techniques. This research will propose such transformations for hardware and software under various assumptions, and seek to determine when such protection is impossible.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
TWC: Frontier: Collaborative: CORe: Center for Encrypted Functionalities
-
批准号:1413955
-
项目类别:Continuing Grant
-
资助金额:$125.01万
-
财政年份:2014
-
负责人:Amit Sahai
-
依托单位:
TWC: Medium: Collaborative Research: Transformative New Approaches to Efficient Secure Computation
-
批准号:1228984
-
项目类别:Standard Grant
-
资助金额:$60.0万
-
财政年份:2012
-
负责人:Amit Sahai
-
依托单位:
TC: Small: New Directions in Encryption
-
批准号:1118096
-
项目类别:Standard Grant
-
资助金额:$49.54万
-
财政年份:2011
-
负责人:Amit Sahai
-
依托单位:
AF: Small: A Theory of Cryptography and the Physical World
-
批准号:0916574
-
项目类别:Standard Grant
-
资助金额:$40.0万
-
财政年份:2009
-
负责人:Amit Sahai
-
依托单位:
CT-ISG: New Directions in Cryptographic Proof Systems
-
批准号:0627781
-
项目类别:Continuing Grant
-
资助金额:$35.0万
-
财政年份:2006
-
负责人:Amit Sahai
-
依托单位:
ITR: New Directions in Software Security
-
批准号:0456717
-
项目类别:Continuing Grant
-
资助金额:$0.0万
-
财政年份:2004
-
负责人:Amit Sahai
-
依托单位:
海外基金