课题基金 / 基金详情

CRII: SaTC: Rethinking Side Channel Security on Untrusted Operating Systems

CRII: SaTC: Rethinking Side Channel Security on Untrusted Operating Systems
CRII:SaTC:重新思考不可信操作系统上的侧通道安全
批准号:
1566444
负责人:
Yinqian Zhang
金额:
$17.5万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2016
资助国家:
美国
项目状态:
已结题
起止时间:
2016-05-01 至 2018-04-30

项目摘要

项目成果

Yinqian Zhang的其他基金

相似基金

相关文献

中文摘要
翻译
隔离执行技术的最新进展,特别是英特尔软件保护扩展(SGX)的出现,彻底改变了计算机安全模型,并使具有敏感数据和代码的程序免受不受信任的操作系统的攻击。然而,对于臭名昭著的信息泄漏侧信道攻击,它们的安全保障还没有得到彻底的研究。可以想象,完全控制底层操作系统的侧信道攻击比来自非特权程序的攻击更多样化、更高效、更健壮。因此,侧通道安全性或缺乏侧通道安全性将显著影响此类技术所提供的安全性承诺。该研究项目的目标是通过(1)系统地、自动地使用模型检查技术识别新的侧通道攻击向量,(2)检查特权攻击者的新能力,从而充分了解在不受信任的操作系统上这种孤立执行环境中侧通道信息泄漏的风险,这些攻击可能导致更强大、更有效的侧通道攻击。(3)提高我们对潜在背景下潜在解决方案对侧信道威胁的有效性的理解。该研究提出了系统评估计算机系统侧信道安全性的新框架,并提供了对不可信操作系统侧信道漏洞的新见解。更广泛地说,该项目将为新交所的行业实践提供指导方针,并整合PI?我们对STEM教育的研究。
英文摘要
Recent advances of isolated execution technologies, especially the emergence of Intel Software Guard eXtension (SGX), revolutionize the model of computer security and empower programs with sensitive data and code to be shielded from untrusted operating systems. However, their security guarantees have not yet been thoroughly investigated against the notorious vector of information leakage side-channel attacks. It is conceivable that side-channel attacks with full control of the underlying operating system are more diverse, efficient and robust than those from unprivileged programs. As a result, side-channel security, or lack thereof, will significantly impact the security promises offered by such technologies.The objective of the research project is to fully understand risks of side-channel information leakage in such isolated execution environments on untrusted operating systems, by (1) identifying new side-channel attack vectors systematically and automatically using model checking techniques, (2) examining new capabilities of privileged attackers that may lead to more robust and efficient side-channel attacks, and (3) advancing our understanding of the effectiveness of potential solutions to side-channel threats in the underlying context. The study conceptualizes new frameworks for systematically evaluating side-channel security of computer systems, and also provides new insights on side-channel vulnerabilities on untrusted operating systems. More broadly, the project will offer guidelines for industry practices of SGX and an integration of the PI?s research into STEM education.
期刊论文(3)
专著(0)
科研奖励(0)
会议论文
DOI: --
发表时间: 2016
期刊:
影响因子: --
作者: [Yuan Xiao;Xiaokuan Zhang;Yinqian Zhang;R. Teodorescu]
通讯作者: Yuan Xiao;Xiaokuan Zhang;Yinqian Zhang;R. Teodorescu
CAREER: Taming the Side-Channel Hazards in the Shielded Execution Paradigm
  • 批准号:
    1750809
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $50.0万
  • 财政年份:
    2018
  • 负责人:
    Yinqian Zhang
  • 依托单位:
CSR: Small: Self-Monitoring Virtual Machines for Performance Guarantees in Public Clouds
  • 批准号:
    1718084
  • 项目类别:
    Standard Grant
  • 资助金额:
    $50.0万
  • 财政年份:
    2017
  • 负责人:
    Yinqian Zhang
  • 依托单位:
海外基金