CAREER: Language-based Distributed System Security
CAREER: Language-based Distributed System Security
批准号:
0346939
负责人:
Stephan Zdancewic
金额:
$40.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2004
资助国家:
美国
项目状态:
已结题
起止时间:
2004-06-01 至 2009-05-31
中文摘要
CNS-0346939 CAREER:基于数据库的分布式系统安全Stephan A.分布式系统是现代计算基础设施中越来越重要的一部分,但现有的技术缺乏确保其安全性和可靠性。 本研究解决了构建分布式系统的问题,并通过开发编程语言来推理其安全性,这些编程语言为描述安全策略和通信协议提供了更好的抽象。 这个项目的出发点是现有的安全类型语言的工作,它保护数据的机密性和完整性。 这项研究概括了这些信息流策略,使它们更具动态性,使它们能够适应分布式系统运行的不断变化的环境。 例如,动态信息流策略应该与传统的身份验证和访问控制机制干净地结合起来,以提供端到端的保密保证。该项目的第二阶段是开发将动态安全策略应用于分布式程序的语言技术。这部分研究的想法是开发一个理论基础,为安全的分布式计算使用现有的进程calculi增强了异构的信任模型和上述的政策语言。 在这种设置中,类型描述通信协议,其属性可以由编译器静态验证。 其结果将是一种具有良好类型规范的编程语言,有助于程序员编写正确的、安全关键的分布式程序。
英文摘要
CNS-0346939CAREER: Language-based Distributed System SecurityStephan A. ZdancewicDistributed systems are an increasingly crucial part of moderncomputing infrastructure, yet the existing technology for ensuringtheir security and reliability is lacking. This research addressesthe problem of building distributed systems and reasoning about theirsecurity by developing programming languages that provide betterabstractions for describing security policies and communicationprotocols. The starting point for this project is existing work on security-typedlanguages, which protect data confidentiality and integrity. Thisresearch generalizes these information-flow policies to make them moredynamic, enabling them to accommodate the changing environment in whichdistributed systems run. For example, dynamic information-flowpolicies should integrate cleanly with traditional authentication andaccess control mechanisms to provide end-to-end guarantees about dataconfidentiality.The second stage of this project is to develop language technologythat applies dynamic security policies to distributed programs. Theidea for this part of the research is to develop a theoretical basisfor secure distributed computing using existing process calculiaugmented with a heterogeneous trust model and the policy languageoutlined above. In this setting, types describe communicationprotocols, properties of which can be verified statically by thecompiler. The result will be a programming language with a sound typesystem that aids the programmer in writing correct, security-criticaldistributed programs.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
REU Site: Research Experience for undergraduates in Programming Languages (REPL)
-
批准号:2244494
-
项目类别:Standard Grant
-
资助金额:$32.21万
-
财政年份:2023
-
负责人:Stephan Zdancewic
-
依托单位:
SaTC: CORE: Medium: Secure and Formally-verified Low-level Languages
-
批准号:2247088
-
项目类别:Standard Grant
-
资助金额:$120.0万
-
财政年份:2023
-
负责人:Stephan Zdancewic
-
依托单位:
Student Travel for Programming Languages Mentoring Workshop at ACM SIGACT-SIGPLAN Symposium on Principles of Programming Languages, 2019 (PLMW@POPL)
-
批准号:1841603
-
项目类别:Standard Grant
-
资助金额:$1.5万
-
财政年份:2018
-
负责人:Stephan Zdancewic
-
依托单位:
NSF Student Travel Grant for 2018 Programming Languages
-
批准号:1749155
-
项目类别:Standard Grant
-
资助金额:$1.5万
-
财政年份:2017
-
负责人:Stephan Zdancewic
-
依托单位:
SHF: SMALL: NONSTANDARD COMPUTATIONAL MODELS OF LINEAR LOGIC
-
批准号:1421193
-
项目类别:Standard Grant
-
资助金额:$45.0万
-
财政年份:2014
-
负责人:Stephan Zdancewic
-
依托单位:
CCF: Medium: Validating Program Transformations in a Mechanized LLVM
-
批准号:1065166
-
项目类别:Standard Grant
-
资助金额:$80.7万
-
财政年份:2011
-
负责人:Stephan Zdancewic
-
依托单位:
TC: Small: WATCHDOG: Hardware-Assisted Prevention of All Use-After-Free Security Vulnerabilities
-
批准号:1116682
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2011
-
负责人:Stephan Zdancewic
-
依托单位:
SHF: SMALL: Practical Linear Types for Safe Protocols
-
批准号:1017027
-
项目类别:Standard Grant
-
资助金额:$30.0万
-
财政年份:2010
-
负责人:Stephan Zdancewic
-
依托单位:
Unifying Events and Threads: Language Support for Network Services
-
批准号:0541040
-
项目类别:Standard Grant
-
资助金额:$0.0万
-
财政年份:2006
-
负责人:Stephan Zdancewic
-
依托单位:
CT-T: Resource-Guided Implementation of Secure Embedded Software
-
批准号:0524059
-
项目类别:Continuing Grant
-
资助金额:$100.0万
-
财政年份:2005
-
负责人:Stephan Zdancewic
-
依托单位:
Collaborative Research: CT-T: Flexible, Decentralized Information-flow Control for Dynamic Environments
-
批准号:0524035
-
项目类别:Standard Grant
-
资助金额:$30.0万
-
财政年份:2005
-
负责人:Stephan Zdancewic
-
依托单位:
Dynamic Security Policies
-
批准号:0311204
-
项目类别:Continuing Grant
-
资助金额:$30.0万
-
财政年份:2003
-
负责人:Stephan Zdancewic
-
依托单位:
海外基金