Collaborative Proposal: SaTC: Frontiers: Center for Distributed Confidential Computing (CDCC)
Collaborative Proposal: SaTC: Frontiers: Center for Distributed Confidential Computing (CDCC)
批准号:
2207202
负责人:
Zhiqiang Lin
金额:
$88.0万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2022
资助国家:
美国
项目状态:
未结题
起止时间:
2022-10-01 至 2027-09-30
中文摘要
人工智能和大数据分析的进步依赖于数据共享,而数据共享可能会受到隐私问题的阻碍。隐私保护方面最具挑战性的是对正在使用的数据的保护,因为即使是加密的数据也需要在使用之前进行解密,从而将数据内容暴露给未经授权的各方。应对这一挑战的实用且可扩展的解决方案将改变计算,实现前所未有的功能,如机密外包、可信计算服务以及机密或隐私保护协作。为了寻求这样的数据保护圣杯,这个前沿项目建立了多机构和多学科的分布式机密计算中心(CDCC),以创建一个研究、教育、知识转移和劳动力发展环境,基于云和边缘系统上的可信执行环境(TEE)实现可扩展、实用、可验证和可用的使用中数据保护。CDCC专注于分布式机密计算(DCC)的四个基本构建块推力,而不考虑具体的TEE硬件,包括TEE代码的保证、TEE节点的保证、TEE工作流的保证和利益相关者的保证。第一个推力导致了TEE代码认证的开放生态系统,不依赖于任何可信的方,而是依赖于一个值得信赖的应用程序商店,其认证操作是公开的、可问责的和可验证的。第二个重点是开发新的动态数据使用策略模型和实施机制,用于在运行认证代码的TEE节点上进行可伸缩的信任管理和数据控制。第三个重点是确保建立在TEE节点上的计算工作流得到保护,最后一个重点是研究利益相关者的偏好和期望,以指导DCC技术的设计并确保其可用性。在这些构建块之上,该中心探索要启用的各种变革性应用程序(例如,针对医疗保健的机密分布式人工智能支持)。CDCC还在外展方面做出了许多努力(开发大型在线开放课程、行业合作等)。这一奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Advances in AI and big data analytics rely on data sharing, which can be impeded by privacy concerns. Most challenging in privacy protection is protection of data-in-use, since even encrypted data needs to be decrypted before it can be utilized, thereby exposing data content to unauthorized parties. A practical and scalable solution to the challenge will transform computing, enabling unprecedented capabilities such as confidential outsourcing, trusted computing services, and confidential or privacy-preserving collaboration. In quest of such a holy grail of data protection, this frontier project establishes multi-institution and multi-disciplinary Center for Distributed Confidential Computing (CDCC) to create a research, education, knowledge transfer and workforce development environment that enables scalable, practical, verifiable and usable data-in-use protection based upon Trusted Execution Environments (TEE) on cloud and edge systems. CDCC focuses on four building block thrusts fundamental to distributed confidential computing (DCC), regardless of specific TEE hardware, including assurance of TEE code, assurance of TEE nodes, assurance of a TEE workflow and assurance for the stakeholder. The first thrust leads to an open ecosystem for TEE code certification, not relying on any trusted party but on a trustworthy application store whose certification operations are public, accountable and verifiable. The second thrust aims to develop novel dynamic data-use policy models and enforcement mechanisms for scalable trust management and data control on the TEE nodes running certified code. The third thrust focuses on ensuring protection of the computational workflow built on TEE nodes and the last thrust studies the stakeholder's preference and expectations to guide the design of DCC technologies and ensure their usability. On top of these building blocks, the center explores various transformative applications (e.g., confidential distributed AI supports for healthcare) to be enabled. CDCC also has a number of efforts for outreach (development of a massive open online course, industry collaboration, etc.) and for broadening participation (security and privacy lab for attracting minority students, joint summer schools and others).This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(2)
专著(0)
科研奖励(0)
会议论文
DOI:
10.1007/978-3-031-35504-2_3
发表时间:
2023
期刊:
影响因子:
--
作者:
[Wubing Wang;Mengyuan Li;Yinqian Zhang;Zhiqiang Lin]
通讯作者:
Wubing Wang;Mengyuan Li;Yinqian Zhang;Zhiqiang Lin
DOI:
--
发表时间:
2023
期刊:
影响因子:
--
作者:
[Shixuan Zhao;Pinshen Xu;Guoxing Chen;Mengya Zhang;Yinqian Zhang;Zhiqiang Lin]
通讯作者:
Shixuan Zhao;Pinshen Xu;Guoxing Chen;Mengya Zhang;Yinqian Zhang;Zhiqiang Lin
Collaborative Research: EAGER: Towards Safeguarding the Emerging Miniapp Paradigm in Mobile Super Apps
-
批准号:2330264
-
项目类别:Standard Grant
-
资助金额:$15.0万
-
财政年份:2023
-
负责人:Zhiqiang Lin
-
依托单位:
Collaborative Research: PPoSS: Planning: Scaling Autonomous Vehicle Systems at the Edge: from On-Board Processing to Cloud Infrastructure
-
批准号:2118491
-
项目类别:Standard Grant
-
资助金额:$4.24万
-
财政年份:2021
-
负责人:Zhiqiang Lin
-
依托单位:
EDU: Collaborative: Using Virtual Machine Introspection for Deep Cyber Security Education
-
批准号:1834214
-
项目类别:Standard Grant
-
资助金额:$11.09万
-
财政年份:2018
-
负责人:Zhiqiang Lin
-
依托单位:
TWC: Medium: Collaborative: Systems, Tools, and Techniques for Executing, Managing, and Securing SGX Programs
-
批准号:1834213
-
项目类别:Standard Grant
-
资助金额:$46.15万
-
财政年份:2018
-
负责人:Zhiqiang Lin
-
依托单位:
SDI-CSCS: Collaborative Research: S2OS Enabling Infrastructure-Wide Programmable Security with SDI
-
批准号:1834216
-
项目类别:Continuing Grant
-
资助金额:$39.34万
-
财政年份:2018
-
负责人:Zhiqiang Lin
-
依托单位:
CAREER: A Dual-VM Binary Code Reuse Based Framework for Automated Virtual Machine Introspection
-
批准号:1834215
-
项目类别:Continuing Grant
-
资助金额:$48.8万
-
财政年份:2018
-
负责人:Zhiqiang Lin
-
依托单位:
SDI-CSCS: Collaborative Research: S2OS Enabling Infrastructure-Wide Programmable Security with SDI
-
批准号:1700507
-
项目类别:Continuing Grant
-
资助金额:$40.0万
-
财政年份:2017
-
负责人:Zhiqiang Lin
-
依托单位:
TWC: Medium: Collaborative: Systems, Tools, and Techniques for Executing, Managing, and Securing SGX Programs
-
批准号:1564112
-
项目类别:Standard Grant
-
资助金额:$52.82万
-
财政年份:2016
-
负责人:Zhiqiang Lin
-
依托单位:
EDU: Collaborative: Using Virtual Machine Introspection for Deep Cyber Security Education
-
批准号:1623325
-
项目类别:Standard Grant
-
资助金额:$14.99万
-
财政年份:2016
-
负责人:Zhiqiang Lin
-
依托单位:
CI-P: Collaborative: A Community-Driven Open Research Infrastructure for Intel SGX
-
批准号:1629951
-
项目类别:Standard Grant
-
资助金额:$5.0万
-
财政年份:2016
-
负责人:Zhiqiang Lin
-
依托单位:
CAREER: A Dual-VM Binary Code Reuse Based Framework for Automated Virtual Machine Introspection
-
批准号:1453011
-
项目类别:Continuing Grant
-
资助金额:$53.51万
-
财政年份:2015
-
负责人:Zhiqiang Lin
-
依托单位:
海外基金