TWC: Medium: Collaborative: Black-Box Evaluation of Cryptographic Entropy at Scale
TWC: Medium: Collaborative: Black-Box Evaluation of Cryptographic Entropy at Scale
批准号:
1937622
负责人:
Hovav Shacham
金额:
$7.36万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2018
资助国家:
美国
项目状态:
已结题
起止时间:
2018-09-01 至 2019-09-30
中文摘要
生成随机数——掷硬币——的能力对于许多计算任务至关重要,从蒙特卡洛模拟到安全通信。建立这样的子系统来产生随机数的理论是很容易理解的,但是理论和实践之间的差距是惊人的大。正如今天所构建的那样,这些子系统是不透明和脆弱的。这些子系统中的缺陷可能危及数百万Internet主机的安全。该项目将开发黑盒技术,用于在互联网规模上寻找与随机性相关的熵失效。这些技术建立在编程语言、操作系统、网络、安全性和密码学的基础上,然后将被应用于对随机数生成漏洞的状态进行系统的、持续的普查。通过这种普查,该项目可以分析部署的网络系统的“长尾”,而不是先验地选择少数几个。该项目将开发和传播防御性分析工具,帮助程序员在发布代码之前调试和纠正代码中的熵问题。它将产生加密对策和熵收集子系统,提供比现有系统更好的安全保证,减少那些熵失败的影响。结果将是更好地理解熵和更值得信赖的系统,无论是现在还是将来。
英文摘要
The ability to generate random numbers -- to flip coins -- is crucial for many computing tasks, from Monte Carlo simulation to secure communications. The theory of building such subsystems to generate random numbers is well understood, but the gap between theory and practice is surprisingly wide. As built today, these subsystems are opaque and fragile. Flaws in these subsystems can compromise the security of millions of Internet hosts.This project will develop black-box techniques for finding entropy failures at Internet scale related to randomness. These techniques, which build on programming languages, operating systems, networking, security, and cryptography, will then be applied to perform a systematic, ongoing census of the state of random number generation vulnerabilities. Through this census, the project can analyze the "longtail" of deployed networked systems rather than a handful chosen a priori.The project will develop and disseminate defensive analysis tools that will help programmers debug and correct entropy problems in their code before they ship it. It will produce cryptographic countermeasures and entropy-gathering subsystems that provide better security guarantees than existing systems, reducing the impact of those entropy failures that do slip through.The result will be a better understanding of entropy and more trustworthy systems, today and in the future.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: SaTC: CORE: Large: Building and Deploying a Verified JavaScript Runtime
-
批准号:2120696
-
项目类别:Continuing Grant
-
资助金额:$172.99万
-
财政年份:2021
-
负责人:Hovav Shacham
-
依托单位:
TWC: Medium: Collaborative: Black-Box Evaluation of Cryptographic Entropy at Scale
-
批准号:1410031
-
项目类别:Standard Grant
-
资助金额:$38.4万
-
财政年份:2014
-
负责人:Hovav Shacham
-
依托单位:
InfoSec Scholars: Scholarship for Service
-
批准号:1303328
-
项目类别:Continuing Grant
-
资助金额:$213.6万
-
财政年份:2013
-
负责人:Hovav Shacham
-
依托单位:
CT-ISG: Memory Safety for Legacy Software, A Quantitative Approach
-
批准号:0831532
-
项目类别:Continuing Grant
-
资助金额:$40.0万
-
财政年份:2008
-
负责人:Hovav Shacham
-
依托单位:
海外基金