CICI: UCSS: Confidential Computing in Reproducible Collaborative Workflows
CICI: UCSS: Confidential Computing in Reproducible Collaborative Workflows
批准号:
2232824
负责人:
Keke Chen
金额:
$60.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2023
资助国家:
美国
项目状态:
未结题
起止时间:
2023-01-01 至 2025-12-31
中文摘要
数据密集型科研项目往往涉及多个协作方。一些缔约方可能要求对其敏感资产进行保密处理以保护知识产权,在发表论文前禁止数据(或算法)共享,符合法律要求,或逃避发布敏感数据的责任。然而,将机密计算集成到科学工作流程中会带来巨大的挑战。(1)大多数科学领域的开发人员发现,学习特定的机密计算框架并保护他们的代码免受旁路攻击是一件具有挑战性的事情。(2)在协作工作流中,私有组件和其他组件之间的相互作用可能会使攻击者能够发现新的攻击和旁路。拟议的项目旨在通过一个科学家友好的机密计算开发框架和一个协作工作流程的整体攻击研究和缓解框架来应对这些挑战。该项目的成功将使领域科学家开发者能够轻松地采用最好的保密计算实践并使用公开可用的资源,而无需担心机密性和隐私泄露,从而促进了开放、协作科学的理念。具体地说,该研究着眼于基于科学家的可信执行环境(TEE)的开发,并研究其与协同科学工作流的集成。(1)该项目为领域科学家探索不同的保护和可用性解决方案,并允许他们在他们的研究目标和安全和隐私问题之间进行权衡。(2)它开发了一个高效和透明的TEE访问模式保护框架,该框架独特地结合了数据密集型计算的最佳实践和基于框架的缓解方法。(3)从整体上研究协同工作流中机密组件面临的新的安全和隐私威胁,包括任务执行、日志记录、来源分析和可重复性验证等阶段。这些解决方案将整合TEE、区块链和差异隐私等技术。(4)它是由科学驱动的,受到生物医学序列处理、基于图像的远程诊断和医疗数据分析方面的合作研究项目的激励和验证。该项目将生成开源工具包和演示系统。它还包括几个教育和推广倡议,以加强网络安全和数据科学项目,吸引代表性不足的学生,帮助当地高中CS教育,并加强行业合作。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Data-intensive scientific research projects often involve multiple collaborative parties. Some parties may demand confidential processing of their sensitive assets to protect intellectual property, embargo data (or algorithm) sharing before publishing a paper, conform to legal requirements, or avoid the responsibility for releasing sensitive data. However, integrating confidential computing into scientific workflows raises significant challenges. (1) Most science domain developers find it challenging to learn specific confidential computing frameworks and secure their code to protect from side-channel attacks. (2) The interplay between the private components and other components in a collaborative workflow may enable new attacks and side channels for adversaries to explore. The proposed project aims to address these challenges with a scientist-friendly development framework for confidential computing and a holistic attack study and mitigation framework for collaborative workflows. The success of this project will enable domain scientist developers to adopt the best confidential computing practices easily and use publicly available resources without the concern of confidentiality and privacy breach, boosting the idea of open, collaborative science.Specifically, the proposed research focuses on the scientist-oriented trusted-execution-environment (TEE) based development and studies its integration with collaborative scientific workflows. (1) The project explores different protection and usability solutions for domain scientists and allows them to tradeoff between their research goals and security and privacy concerns. (2) It develops an efficient and transparent TEE access-pattern protection framework that uniquely combines the best practices in data-intensive computing and framework-based mitigation methods. (3) It takes a holistic approach to study new security and privacy threats around confidential components in a collaborative workflow, covering stages including task execution, logging, provenance analysis, and reproducibility verification. The solutions will integrate techniques like TEE, blockchain, and differential privacy. (4) It is science-driven, motivated, and validated by collaborative research projects in biomedical sequence processing, image-based remote diagnosis, and healthcare data analytics. This project will generate open-source toolkits and demonstration systems. It also includes several educational and outreach initiatives to enhance cybersecurity and data science programs, attract underrepresented students, help local high school CS education, and strengthen industrial collaborations.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(5)
专著(0)
科研奖励(0)
会议论文
Demo: SGX-MR-Prot: Efficient and Developer-Friendly Access-Pattern Protection in Trusted Execution Environments
演示:SGX-MR-Prot:可信执行环境中高效且开发人员友好的访问模式保护
DOI:
10.1109/icdcs57875.2023.00121
发表时间:
2023
期刊:
IEEE
影响因子:
--
作者:
[Alam, A K, Boyce, Justin, Chen, Keke]
通讯作者:
Chen, Keke
DOI:
10.1109/mic.2022.3226757
发表时间:
2022-12
期刊:
IEEE Internet Computing
影响因子:
3.2
作者:
[Keke Chen]
通讯作者:
Keke Chen
GAN-Based Domain Inference Attack
基于 GAN 的域推理攻击
DOI:
10.1609/aaai.v37i12.26663
发表时间:
2023
期刊:
Proceedings of the AAAI Conference on Artificial Intelligence
影响因子:
--
作者:
[Gu, Yuechun, Chen, Keke]
通讯作者:
Chen, Keke
CUTE: Instructional Laboratories for Cloud Computing Education
-
批准号:1245847
-
项目类别:Standard Grant
-
资助金额:$20.0万
-
财政年份:2013
-
负责人:Keke Chen
-
依托单位:
海外基金