SaTC: CORE: Small: API-centric Cryptography
SaTC: CORE: Small: API-centric Cryptography
批准号:
1816375
负责人:
Thomas Shrimpton
金额:
$45.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2018
资助国家:
美国
项目状态:
已结题
起止时间:
2018-10-01 至 2023-09-30
中文摘要
密码学是现代技术的核心组成部分。它保护互联网交易,隐藏用户名和密码穿越网络,保护驻留在移动设备和计算机磁盘驱动器上的数据,等等。密码机制负责保护的系统通常非常复杂,有许多相互作用的部分和大量可能易受攻击的地方(通常称为“攻击面”)。这个庞大的攻击面的一个要素是,研究人员设计的数学算法与声称实现这些强大算法的软件之间存在连接(或断开)。当软件不能准确地实现数学算法时,在实践中可能会出现很多问题。这导致了现实世界的攻击,尽管数学证明不应该有这样的攻击。这项研究的两个主要主题是:(1)对数学算法及其实现之间的这种脱节的普遍程度进行广泛和深入的了解;(2)重塑研究人员对他们的理论工作的思考方式,使他们开发的东西更难出错,更容易理解,更容易验证。更具体地说,到目前为止,安全工程师和开发人员有责任理解和正确实现理论上被证明是安全的加密原语和协议,并根据需要重塑他们现有的代码库和应用程序编程接口(API)。这个项目探索了另一种观点:由于现实世界的库及其API必然是僵化的,理论上有责任尊重这一点。此外,正确实现的简易性应该是主要的设计目标。只要有可能,理论原语应该对缺乏密码学专业知识的开发人员的误解具有弹性。具体来说,这项工作包括三项主要任务。第一种是将这种“以API为中心”的观点应用于几个重要的原语,例如安全通道和认证密钥交换。它还包括调查现有标准、库和软件构件的工作。第二项任务寻求开发能够原谅其误用的理论原语(例如,面对糟糕的随机性时稳健的原语,以及本机处理高度结构化的明文数据的原语)。第三项任务是开发加密原语的抽象语法,该抽象语法对于需要在实践中实施的真实功能是“深思熟虑的”。这一奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Cryptography is a core component of modern technology. It protects internet transactions, hides usernames and passwords as they traverse networks, protects the data residing on mobile devices and computer disk drives, and much more. The systems that cryptographic mechanisms are tasked with protecting are typically very complex, with many interacting parts and a large number of places that may be vulnerable (often called the "attack surface"). One element of this large attack surface is the connection (or disconnection) between the mathematical algorithms that researchers design and the software that purports to implement these powerful algorithms. When the software fails to accurately implement the mathematical algorithms, much can go wrong in practice. This has led to real-world attacks, even though mathematics proves that no such attacks should be possible. The two main themes of this research are: (1) to develop a broad and deep view of just how prevalent these disconnections are between the mathematical algorithms and their implementation, and (2) to reshape the way that researchers think about their theoretical efforts, so that what they develop is harder for software developers to get wrong, easier to understand, and easier to validate.More specifically, to date the onus is on the security engineers and developers to understand and correctly realize the cryptographic primitives and protocols that are provably secure in theory, and to reshape their existing code base and application programming interfaces (APIs) as required. This project explores an alternative viewpoint: as real-world libraries and their APIs are necessarily inflexible, the onus is to be on the theory to respect this. Moreover, ease of correct implementation ought to be a primary design goal. Whenever possible, theoretical primitives should be resilient to misunderstandings by developers who lack expertise in cryptography. Concretely, the work includes three main tasks. The first one applies this "API-centric" viewpoint to several important primitives, e.g., secure channels and authenticated key exchange. It also includes efforts to survey existing standards, libraries, and software artifacts. The second task seeks to develop theoretical primitives that are forgiving of their misuse (e.g., primitives that are robust in the face of bad randomness, and that natively handle highly structured plaintext data). The third task is to develop abstract syntax for cryptographic primitives that is "thoughtful" with respect to the real functionalities that will need to be implemented in practice.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(7)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
Quantifying the Security Cost of Migrating Protocols to Practice
量化将协议迁移到实践的安全成本
DOI:
10.1007/978-3-030-56784-2_4
发表时间:
2020
期刊:
Advances in Cryptology -- CRYPTO 2020
影响因子:
--
作者:
[Patton, Christopher, Shrimpton, Thomas]
通讯作者:
Shrimpton, Thomas
DOI:
10.1145/3133956.3134040
发表时间:
2017-10
期刊:
Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
作者:
[Animesh Chhotaray;Adib Nahiyan;Thomas Shrimpton;Domenic Forte;M. Tehranipoor]
通讯作者:
Animesh Chhotaray;Adib Nahiyan;Thomas Shrimpton;Domenic Forte;M. Tehranipoor
Partially Specified Channels: The TLS 1.3 Record Layer without Elision
部分指定通道:没有省略的 TLS 1.3 记录层
DOI:
10.1145/3243734.3243789
发表时间:
2018
期刊:
Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
作者:
[Patton, Christopher, Shrimpton, Thomas]
通讯作者:
Shrimpton, Thomas
Hardening Circuit-Design IP Against Reverse-Engineering Attacks
强化电路设计 IP 以抵御逆向工程攻击
DOI:
10.1109/sp46214.2022.9833634
发表时间:
2022
期刊:
2022 IEEE Symposium on Security and Privacy
影响因子:
--
作者:
[Chhotaray, Animesh, Shrimpton, Thomas]
通讯作者:
Shrimpton, Thomas
Security in the Presence of Key Reuse: Context-Separable Interfaces and Their Applications
密钥重用的安全性:上下文可分离的接口及其应用
DOI:
--
发表时间:
2019
期刊:
Advances in Cryptology -- CRYPTO 2019 -- 39th Annual International Cryptology Conference
影响因子:
--
作者:
[Patton, Christopher, Shrimpton, Thomas]
通讯作者:
Shrimpton, Thomas
共 7 条
NSF Student Travel Grant for Real World Cryptography 2019 (RWC '19)
-
批准号:1839355
-
项目类别:Standard Grant
-
资助金额:$1.8万
-
财政年份:2019
-
负责人:Thomas Shrimpton
-
依托单位:
NSF Student Travel Grant for Real World Cryptography 2017 (RWC'17)
-
批准号:1703879
-
项目类别:Standard Grant
-
资助金额:$1.8万
-
财政年份:2017
-
负责人:Thomas Shrimpton
-
依托单位:
TWC: Medium: Collaborative: Distribution-Sensitive Cryptography
-
批准号:1514237
-
项目类别:Standard Grant
-
资助金额:$39.98万
-
财政年份:2015
-
负责人:Thomas Shrimpton
-
依托单位:
TWC: Small: Theory and Practice of Tweakable-Blockcipher-Based Cryptography
-
批准号:1564446
-
项目类别:Standard Grant
-
资助金额:$21.26万
-
财政年份:2015
-
负责人:Thomas Shrimpton
-
依托单位:
TWC: Medium: Collaborative: Distribution-Sensitive Cryptography
-
批准号:1564444
-
项目类别:Standard Grant
-
资助金额:$39.98万
-
财政年份:2015
-
负责人:Thomas Shrimpton
-
依托单位:
TWC: Small: Theory and Practice of Tweakable-Blockcipher-Based Cryptography
-
批准号:1319061
-
项目类别:Standard Grant
-
资助金额:$43.38万
-
财政年份:2013
-
负责人:Thomas Shrimpton
-
依托单位:
CAREER: Design Principles for Cryptographic Hash Functions: Foundations, Primitives, and Transforms
-
批准号:0845610
-
项目类别:Continuing Grant
-
资助金额:$40.0万
-
财政年份:2009
-
负责人:Thomas Shrimpton
-
依托单位:
CT: Making Network Layer Proofs-of-Work Work
-
批准号:0627752
-
项目类别:Continuing Grant
-
资助金额:$39.97万
-
财政年份:2006
-
负责人:Thomas Shrimpton
-
依托单位:
国内基金
海外基金
登录
查看更多内容
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
-
批准号:82371765
-
项目类别:面上项目
-
资助金额:50万元
-
批准年份:2023
-
负责人:谭广云
-
依托单位:
锕系元素5f-in-core的GTH赝势和基组的开发
-
批准号:22303037
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2023
-
负责人:鲁俊波
-
依托单位:
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
-
批准号:--
-
项目类别:--
-
资助金额:52万元
-
批准年份:2022
-
负责人:孙丙军
-
依托单位:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
-
批准号:--
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2022
-
负责人:叶成林
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:--
-
项目类别:--
-
资助金额:55万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:82072415
-
项目类别:面上项目
-
资助金额:55.0万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
肌营养不良蛋白聚糖Core M3型甘露糖肽的精确制备及功能探索
-
批准号:92053110
-
项目类别:重大研究计划
-
资助金额:70.0万元
-
批准年份:2020
-
负责人:彭鹏
-
依托单位:
Core-1-O型聚糖黏蛋白缺陷诱导胃炎发生并介导慢性胃炎向胃癌转化的分子机制研究
-
批准号:81902805
-
项目类别:青年科学基金项目
-
资助金额:20.5万元
-
批准年份:2019
-
负责人:刘菲
-
依托单位:
原始地球增生晚期的Core-merging大碰撞事件:地核增生、核幔平衡与核幔边界结构的新认识
-
批准号:41973063
-
项目类别:面上项目
-
资助金额:65.0万元
-
批准年份:2019
-
负责人:周游
-
依托单位:
CORDEX-CORE区域气候模拟与预估研讨会
-
批准号:41981240365
-
项目类别:国际(地区)合作与交流项目
-
资助金额:1.5万元
-
批准年份:2019
-
负责人:陈威霖
-
依托单位: