课题基金 / 基金详情

SaTC: CORE: Small: API-centric Cryptography

SaTC: CORE: Small: API-centric Cryptography
SaTC:核心:小型:以 API 为中心的密码学
批准号:
1816375
负责人:
Thomas Shrimpton
金额:
$45.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2018
资助国家:
美国
项目状态:
已结题
起止时间:
2018-10-01 至 2023-09-30

项目摘要

项目成果

Thomas Shrimpton的其他基金

相似基金

相关文献

中文摘要
翻译
密码学是现代技术的核心组成部分。它保护互联网交易,隐藏用户名和密码穿越网络,保护驻留在移动设备和计算机磁盘驱动器上的数据,等等。密码机制负责保护的系统通常非常复杂,有许多相互作用的部分和大量可能易受攻击的地方(通常称为“攻击面”)。这个庞大的攻击面的一个要素是,研究人员设计的数学算法与声称实现这些强大算法的软件之间存在连接(或断开)。当软件不能准确地实现数学算法时,在实践中可能会出现很多问题。这导致了现实世界的攻击,尽管数学证明不应该有这样的攻击。这项研究的两个主要主题是:(1)对数学算法及其实现之间的这种脱节的普遍程度进行广泛和深入的了解;(2)重塑研究人员对他们的理论工作的思考方式,使他们开发的东西更难出错,更容易理解,更容易验证。更具体地说,到目前为止,安全工程师和开发人员有责任理解和正确实现理论上被证明是安全的加密原语和协议,并根据需要重塑他们现有的代码库和应用程序编程接口(API)。这个项目探索了另一种观点:由于现实世界的库及其API必然是僵化的,理论上有责任尊重这一点。此外,正确实现的简易性应该是主要的设计目标。只要有可能,理论原语应该对缺乏密码学专业知识的开发人员的误解具有弹性。具体来说,这项工作包括三项主要任务。第一种是将这种“以API为中心”的观点应用于几个重要的原语,例如安全通道和认证密钥交换。它还包括调查现有标准、库和软件构件的工作。第二项任务寻求开发能够原谅其误用的理论原语(例如,面对糟糕的随机性时稳健的原语,以及本机处理高度结构化的明文数据的原语)。第三项任务是开发加密原语的抽象语法,该抽象语法对于需要在实践中实施的真实功能是“深思熟虑的”。这一奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Cryptography is a core component of modern technology. It protects internet transactions, hides usernames and passwords as they traverse networks, protects the data residing on mobile devices and computer disk drives, and much more. The systems that cryptographic mechanisms are tasked with protecting are typically very complex, with many interacting parts and a large number of places that may be vulnerable (often called the "attack surface"). One element of this large attack surface is the connection (or disconnection) between the mathematical algorithms that researchers design and the software that purports to implement these powerful algorithms. When the software fails to accurately implement the mathematical algorithms, much can go wrong in practice. This has led to real-world attacks, even though mathematics proves that no such attacks should be possible. The two main themes of this research are: (1) to develop a broad and deep view of just how prevalent these disconnections are between the mathematical algorithms and their implementation, and (2) to reshape the way that researchers think about their theoretical efforts, so that what they develop is harder for software developers to get wrong, easier to understand, and easier to validate.More specifically, to date the onus is on the security engineers and developers to understand and correctly realize the cryptographic primitives and protocols that are provably secure in theory, and to reshape their existing code base and application programming interfaces (APIs) as required. This project explores an alternative viewpoint: as real-world libraries and their APIs are necessarily inflexible, the onus is to be on the theory to respect this. Moreover, ease of correct implementation ought to be a primary design goal. Whenever possible, theoretical primitives should be resilient to misunderstandings by developers who lack expertise in cryptography. Concretely, the work includes three main tasks. The first one applies this "API-centric" viewpoint to several important primitives, e.g., secure channels and authenticated key exchange. It also includes efforts to survey existing standards, libraries, and software artifacts. The second task seeks to develop theoretical primitives that are forgiving of their misuse (e.g., primitives that are robust in the face of bad randomness, and that natively handle highly structured plaintext data). The third task is to develop abstract syntax for cryptographic primitives that is "thoughtful" with respect to the real functionalities that will need to be implemented in practice.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(7)
专著(0)
科研奖励(0)
会议论文
Quantifying the Security Cost of Migrating Protocols to Practice
量化将协议迁移到实践的安全成本
DOI: 10.1007/978-3-030-56784-2_4
发表时间: 2020
期刊: Advances in Cryptology -- CRYPTO 2020
影响因子: --
作者: [Patton, Christopher, Shrimpton, Thomas]
通讯作者: Shrimpton, Thomas
DOI: 10.1145/3133956.3134040
发表时间: 2017-10
期刊: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者: [Animesh Chhotaray;Adib Nahiyan;Thomas Shrimpton;Domenic Forte;M. Tehranipoor]
通讯作者: Animesh Chhotaray;Adib Nahiyan;Thomas Shrimpton;Domenic Forte;M. Tehranipoor
Partially Specified Channels: The TLS 1.3 Record Layer without Elision
部分指定通道:没有省略的 TLS 1.3 记录层
DOI: 10.1145/3243734.3243789
发表时间: 2018
期刊: Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者: [Patton, Christopher, Shrimpton, Thomas]
通讯作者: Shrimpton, Thomas
Hardening Circuit-Design IP Against Reverse-Engineering Attacks
强化电路设计 IP 以抵御逆向工程攻击
DOI: 10.1109/sp46214.2022.9833634
发表时间: 2022
期刊: 2022 IEEE Symposium on Security and Privacy
影响因子: --
作者: [Chhotaray, Animesh, Shrimpton, Thomas]
通讯作者: Shrimpton, Thomas
共 7 条
    NSF Student Travel Grant for Real World Cryptography 2019 (RWC '19)
    • 批准号:
      1839355
    • 项目类别:
      Standard Grant
    • 资助金额:
      $1.8万
    • 财政年份:
      2019
    • 负责人:
      Thomas Shrimpton
    • 依托单位:
    NSF Student Travel Grant for Real World Cryptography 2017 (RWC'17)
    • 批准号:
      1703879
    • 项目类别:
      Standard Grant
    • 资助金额:
      $1.8万
    • 财政年份:
      2017
    • 负责人:
      Thomas Shrimpton
    • 依托单位:
    TWC: Medium: Collaborative: Distribution-Sensitive Cryptography
    • 批准号:
      1514237
    • 项目类别:
      Standard Grant
    • 资助金额:
      $39.98万
    • 财政年份:
      2015
    • 负责人:
      Thomas Shrimpton
    • 依托单位:
    TWC: Small: Theory and Practice of Tweakable-Blockcipher-Based Cryptography
    • 批准号:
      1564446
    • 项目类别:
      Standard Grant
    • 资助金额:
      $21.26万
    • 财政年份:
      2015
    • 负责人:
      Thomas Shrimpton
    • 依托单位:
    国内基金
    海外基金
    胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
    • 批准号:
      82371765
    • 项目类别:
      面上项目
    • 资助金额:
      50万元
    • 批准年份:
      2023
    • 负责人:
      谭广云
    • 依托单位:
    锕系元素5f-in-core的GTH赝势和基组的开发
    • 批准号:
      22303037
    • 项目类别:
      青年科学基金项目
    • 资助金额:
      30万元
    • 批准年份:
      2023
    • 负责人:
      鲁俊波
    • 依托单位:
    基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
    • 批准号:
      --
    • 项目类别:
      --
    • 资助金额:
      52万元
    • 批准年份:
      2022
    • 负责人:
      孙丙军
    • 依托单位:
    鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
    • 批准号:
      --
    • 项目类别:
      青年科学基金项目
    • 资助金额:
      30万元
    • 批准年份:
      2022
    • 负责人:
      叶成林
    • 依托单位: