TWC: Medium: Automating Countermeasures and Security Evaluation Against Software Side-channel Attacks
TWC: Medium: Automating Countermeasures and Security Evaluation Against Software Side-channel Attacks
批准号:
1563697
负责人:
Yunsi Fei
金额:
$120.0万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2016
资助国家:
美国
项目状态:
已结题
起止时间:
2016-06-01 至 2021-05-31
中文摘要
侧通道攻击(SCA)已经成为各种不具备专用保护功能的加密实现的现实威胁。虽然已经找到了许多有效的对策并手动应用,但它们是针对特定应用和劳动密集型的。此外,安全评估往往是不完整的,无法保证目标系统中的所有漏洞都已通过这种手动对策进行识别和解决。SATC项目旨在转变侧通道攻击的研究范式,提出建立一个针对软件侧通道攻击的信息泄露分析、多层次对抗应用和形式化安全评估的自动化框架,该框架提供了通用的信息泄露的可靠度量、自动对策的方法论以及形式化和透彻的评估方法。该方法将功耗分析和基于缓存的定时攻击统一到一个框架中。它定义了新的信息泄漏度量,并使用它们在没有实现细节的情况下在早期阶段自动识别给定密码系统可能的泄漏。传统的编译过程沿着安全性优化的新维度进行扩展,以生成侧通道弹性代码并确保其在运行时的安全执行。采用形式化方法保证了旁信道的安全性处于一定的置信度水平。团队中的三名研究人员为这项具有挑战性的跨学科研究带来了互补的专业知识,以开发高级自动化框架和相关的软件工具、指标和方法。这一结果大大有利于安全系统架构师和软件开发人员将可验证的SCA安全性构建到他们设计的广泛应用程序中。该项目还在基础统计、形式方法和实际系统安全之间建立了新的协同效应。当自动化工具被引入到PI开发的新课程中时,有助于极大地改善学生的动手体验。该项目还利用东北大学的体验式教育模式,让本科生、女性和少数民族学生参与独立研究项目。
英文摘要
Side-channel attacks (SCA) have been a realistic threat to various cryptographic implementations that do not feature dedicated protection. While many effective countermeasures have been found and applied manually, they are application-specific and labor intensive. In addition, security evaluation tends to be incomplete, with no guarantee that all the vulnerabilities in the target system have been identified and addressed by such manual countermeasures. This SaTC project aims to shift the paradigm of side-channel attack research, and proposes to build an automation framework for information leakage analysis, multi-level countermeasure application, and formal security evaluation against software side-channel attacks.The proposed framework provides common sound metrics for information leakage, methodologies for automatic countermeasures, and formal and thorough evaluation methods. The approach unifies power analysis and cache-based timing attacks into one framework. It defines new metrics of information leakage and uses them to automatically identify possible leakage of a given cryptosystem at an early stage with no implementation details. The conventional compilation process is extended along the new dimension of optimizing for security, to generate side-channel resilient code and ensure its secure execution at run-time. Side-channel security is guaranteed to be at a certain confidence level with formal methods. The three investigators on the team bring complementary expertise to this challenging interdisciplinary research, to develop the advanced automation framework and the associated software tools, metrics, and methodologies. The outcome significantly benefits security system architects and software developers alike, in their quest to build verifiable SCA security into a broad range of applications they design. The project also builds new synergy among fundamental statistics, formal methods, and practical system security. The automation tools, when introduced in new courses developed by the PIs, help improving students' hands-on experience greatly. The project also leverages the experiential education model of Northeastern University to engage undergraduates, women, and minority students in independent research projects.
期刊论文(1)
专著(0)
科研奖励(0)
会议论文
DOI:
10.2478/popets-2022-0025
发表时间:
2021-11
期刊:
Proceedings on Privacy Enhancing Technologies
影响因子:
--
作者:
[Konstantinos Athanasiou;T. Wahl;A. Ding;Yunsi Fei]
通讯作者:
Konstantinos Athanasiou;T. Wahl;A. Ding;Yunsi Fei
EAGER: Side Channels Go Deep - Leveraging Deep Learning for Side-channel Analysis and Protection
-
批准号:2212010
-
项目类别:Standard Grant
-
资助金额:$30.0万
-
财政年份:2022
-
负责人:Yunsi Fei
-
依托单位:
SaTC: CORE: Medium: Protecting Confidentiality and Integrity of Deep Neural Networks against Side-Channel and Fault Attacks
-
批准号:1929300
-
项目类别:Standard Grant
-
资助金额:$120.0万
-
财政年份:2019
-
负责人:Yunsi Fei
-
依托单位:
Phase I IUCRC Northeastern University: Center for Hardware and Embedded System Security and Trust (CHEST)
-
批准号:1916762
-
项目类别:Continuing Grant
-
资助金额:$75.0万
-
财政年份:2019
-
负责人:Yunsi Fei
-
依托单位:
Planning IUCRC Northeastern University: Center for Hardware and Embedded System Security and Trust (CHEST)
-
批准号:1747748
-
项目类别:Standard Grant
-
资助金额:$1.5万
-
财政年份:2018
-
负责人:Yunsi Fei
-
依托单位:
TWC: Medium: Collaborative: A Unified Statistics-Based Framework for Side-Channel Attack Analysis and Security Evaluation of Cryptosystems
-
批准号:1314655
-
项目类别:Standard Grant
-
资助金额:$52.21万
-
财政年份:2013
-
负责人:Yunsi Fei
-
依托单位:
MRI: Development of a Testbed for Side Channel Analysis and Security Evaluation (TeSCASE)
-
批准号:1337854
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2013
-
负责人:Yunsi Fei
-
依托单位:
A Multi-level/multi-faceted Framework for Energy-efficient Application-Specific Instruction Set Processor Synthesis
-
批准号:0541102
-
项目类别:Continuing Grant
-
资助金额:$27.5万
-
财政年份:2006
-
负责人:Yunsi Fei
-
依托单位:
海外基金