课题基金 / 基金详情

TWC: Medium: Collaborative: Neuroscience Meets Computer Security: Designing Systems Secure Against Coercion Attacks

TWC: Medium: Collaborative: Neuroscience Meets Computer Security: Designing Systems Secure Against Coercion Attacks
TWC:媒介:协作:神经科学遇见计算机安全:设计安全抵御强制攻击的系统
批准号:
1228645
负责人:
Dan Boneh
金额:
$37.5万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2012
资助国家:
美国
项目状态:
已结题
起止时间:
2012-10-01 至 2017-09-30

项目摘要

项目成果

Dan Boneh的其他基金

相似基金

相关文献

中文摘要
翻译
强迫授权用户透露其秘密身份验证凭据的强制攻击可让攻击者访问受限制的系统。PI正在开发一种新的方法来防止强迫攻击,使用认知心理学中的内隐学习概念。内隐学习是指在对学习的模式没有任何有意识的了解的情况下对模式的学习。使用精心制作的基于键盘的电脑游戏,PI在参与者的大脑中植入一个秘密密码,而参与者没有任何有意识地知道经过训练的密码。这种植入的秘密可以用于身份验证,但参与者不能被强迫透露他们的秘密,因为他们没有意识到它。这个项目探索了在计算机安全中使用内隐学习的三个方向。首先,PI正在开发用于挑战-响应身份验证的隐式学习任务。其次,PI正在试验通过使用现成的脑电设备测量头皮上的电活动来展示隐性知识的方法。第三,PI正在进行用户实验,以证明参与者能够正确地进行身份验证,但无法有意识地识别训练的秘密。这个项目是计算机安全研究人员和认知心理学家之间的合作。归根结底,该项目的目标是了解大脑如何代表隐性知识。这反过来将导致针对高安全性应用程序的新的抗胁迫安全机制。
英文摘要
Coercion attacks that compel an authorized user to reveal his or her secret authentication credentials can give attackers access to restricted systems. The PIs are developing a new approach to preventing coercion attacks using the concept of implicit learning from cognitive psychology. Implicit learning refers to learning of patterns without any conscious knowledge of the learned pattern. Using a carefully crafted keyboard-based computer game the PIs plant a secret password in the participant's brain without the participant having any conscious knowledge of the trained password. This planted secret can be used for authentication, but participants cannot be coerced into revealing their secret since they have no conscious knowledge of it. This project explores three directions for using implicit learning in computer security. First, the PIs are developing implicit learning tasks designed to be used in challenge-response authentication. Second, the PIs are experimenting with methods to demonstrate implicit knowledge by measuring electrical activity along the scalp using off the shelf EEG devices. Third, the PIs are conducting user experiments to demonstrate that participants are able to properly authenticate, but cannot consciously recognize the trained secret. This project is a collaboration between computer security researchers and cognitive psychologists. Ultimately, the project aims to understand how the brain represents implicit knowledge. This in turn will lead to new coercion resistant security mechanisms for high-security applications.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SaTC: CORE: Frontier: Collaborative: End-to-End Trustworthiness of Machine-Learning Systems
  • 批准号:
    1804222
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $183.97万
  • 财政年份:
    2018
  • 负责人:
    Dan Boneh
  • 依托单位:
SaTC: CORE: Medium: Collaborative: An Algebraic Approach to Secure Multilinear Maps for Cryptography
  • 批准号:
    1701567
  • 项目类别:
    Standard Grant
  • 资助金额:
    $40.0万
  • 财政年份:
    2017
  • 负责人:
    Dan Boneh
  • 依托单位:
TWC: Frontier: Collaborative: CORE: Center for Encrypted Functionalities
  • 批准号:
    1414000
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $95.0万
  • 财政年份:
    2014
  • 负责人:
    Dan Boneh
  • 依托单位:
TWC: Small: Collaborative: Computation and Access Control on Big Multiuser Data
  • 批准号:
    1422255
  • 项目类别:
    Standard Grant
  • 资助金额:
    $10.0万
  • 财政年份:
    2014
  • 负责人:
    Dan Boneh
  • 依托单位:
海外基金