CICI: UCSS: ScienceAccess: Enabling Zero-Trust Resource Access Management for Scientific Collaborations
CICI: UCSS: ScienceAccess: Enabling Zero-Trust Resource Access Management for Scientific Collaborations
批准号:
2232911
负责人:
Gail-Joon Ahn
金额:
$59.17万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2022
资助国家:
美国
项目状态:
未结题
起止时间:
2022-10-01 至 2025-09-30
中文摘要
科学合作通过允许共享各种资源,包括真实数据、高性能计算、网络通道等,极大地促进了科学的发展。由于涉及多个涉众访问这些资源,因此基于一系列访问中介安全策略(am - policy)规范资源共享活动至关重要,这些策略可以满足各种机构、协作团队和研究人员的需求和约束。这种政策驱动的方法将有助于实现科学合作中的重要挑战:资源共享的公平性和处理数字资产的风险管理。然而,这样的am - policy已经以一种特别的、半正式的和不完整的方式被指定、评估和执行:(i)科学家仍然需要编写他们自己的am - policy,而在策略规范中没有表达能力,这使得他们很难正确地表达他们的特定需求。(ii)多个地方机构和管理人员对am政策的评估和执行受到限制。(iii)对系统收集需要在运行时评估策略的安全相关数据的支持也有限。为了应对这些挑战,该项目开发了ScienceAccess,这是一个联邦框架,支持am - policy的存储、检索、评估和实施,允许科学家和管理员以高度自治的方式管理他们的资源共享需求。最终,ScienceAccess试图产生以下结果:(i)阐明am政策的新见解,以便与现有的网络基础设施(包括亚利桑那联邦开放研究计算飞地(AFORCE)和科学DMZ)有效共享资源和现实世界的实验;(ii)新的创新技术,以零信任安全的概念有效地指定、评估和管理am - policy,包括在独立运行的科学机构之间以属性形式自动收集和分发安全相关信息;(iii)未来部署ScienceAccess框架的评估、指南和最佳实践。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Scientific collaborations tremendously contribute to advancing science by allowing to share diverse resources including real data, high-performance computing, network channel, and so on. Since multiple stakeholders are involved in accessing those resources, it is critical to regulate resource sharing activities based on a series of access mediation security policies (AM-Policies) that fulfill requirements and constraints from various institutions, collaborative teams, and researchers. Such policy-driven approach would help achieve important challenges in scientific collaborations: fairness in resource sharing and risk management in dealing with digital assets. However, such AM-Policies have been specified, evaluated and enforced in an ad-hoc, semi-formal, and incomplete way: (i) scientists still need to write their own AM-Policies without having expressiveness power in policy specification, making it difficult for them to correctly articulate their specific needs. (ii) the evaluation and enforcement of AM-Policies across multiple local institutions and administrators are limited. (iii) there is also limited support for systematically collecting security-relevant data that needs to evaluate policies at run-time. To address these challenges, this project develops ScienceAccess, a federated framework supporting the storage, retrieval, evaluation, and enforcement of AM-Policies that allows for scientists and administrators to manage their resource sharing needs with a high degree of autonomy. Ultimately, ScienceAccess attempts to produce the following outcomes: (i) new insights to articulate AM-Policies for effectively sharing resources and real-world experiments with existing cyberinfrastructures including the Arizona Federated Open Research Computing Enclave (AFORCE) and Science DMZ; (ii) new innovative techniques to efficiently specify, evaluate, and manage AM-Policies with the notion of a Zero-Trust security, including the automated collection and distribution of security-relevant information in the form of attributes between independently-run scientific institutions; and (iii) assessments, guidelines, and best practices for future deployments of ScienceAccess framework.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(2)
专著(0)
科研奖励(0)
会议论文
DOI:
10.1109/dsn58367.2023.00035
发表时间:
2023-06
期刊:
2023 53rd Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN)
影响因子:
--
作者:
[Jaejong Baek;P. Soundrapandian;Sukwha Kyung;Ruoyu Wang;Yan Shoshitaishvili;Adam Doupé;Gail-Joon Ahn]
通讯作者:
Jaejong Baek;P. Soundrapandian;Sukwha Kyung;Ruoyu Wang;Yan Shoshitaishvili;Adam Doupé;Gail-Joon Ahn
SpaceMediator: Leveraging Authorization Policies to Prevent Spatial and Privacy Attacks in Mobile Augmented Reality
SpaceMediator:利用授权策略防止移动增强现实中的空间和隐私攻击
DOI:
10.1145/3589608.3593839
发表时间:
2023
期刊:
SACMAT '23: Proceedings of the 28th ACM Symposium on Access Control Models and Technologies
影响因子:
--
作者:
[Claramunt, Luis, Rubio-Medrano, Carlos, Baek, Jaejong, Ahn, Gail-Joon]
通讯作者:
Ahn, Gail-Joon
Collaborative Research: CICI: Secure and Resilient Architecture: SciGuard: Building a Security Architecture for Science DMZ Based on SDN and NFV Technologies
-
批准号:1642031
-
项目类别:Standard Grant
-
资助金额:$49.95万
-
财政年份:2017
-
负责人:Gail-Joon Ahn
-
依托单位:
NSF-SFS: Arizona Cyber Defense Scholarship
-
批准号:1663651
-
项目类别:Continuing Grant
-
资助金额:$399.78万
-
财政年份:2017
-
负责人:Gail-Joon Ahn
-
依托单位:
III: Small: Collaborative Research: Privacy-Aware Collaborative Data Sharing in Human-Centered Social Networks
-
批准号:1527268
-
项目类别:Standard Grant
-
资助金额:$20.0万
-
财政年份:2015
-
负责人:Gail-Joon Ahn
-
依托单位:
Support for the Educational Activities at ACM CCS 2014
-
批准号:1426109
-
项目类别:Standard Grant
-
资助金额:$2.0万
-
财政年份:2014
-
负责人:Gail-Joon Ahn
-
依托单位:
TC: Small: Collaborative Proposal: User-Controlled Persona in Virtual Community
-
批准号:0916688
-
项目类别:Continuing Grant
-
资助金额:$26.99万
-
财政年份:2009
-
负责人:Gail-Joon Ahn
-
依托单位:
CT-M: Collaborative Research: Securing Dynamic Online Social Networks
-
批准号:0831360
-
项目类别:Continuing Grant
-
资助金额:$50.0万
-
财政年份:2008
-
负责人:Gail-Joon Ahn
-
依托单位:
Collaborative Research: Secure Information Sharing in Internet-based Collaborative Applications
-
批准号:0900970
-
项目类别:Continuing Grant
-
资助金额:$6.17万
-
财政年份:2008
-
负责人:Gail-Joon Ahn
-
依托单位:
Collaborative Research: Secure Information Sharing in Internet-based Collaborative Applications
-
批准号:0242393
-
项目类别:Continuing Grant
-
资助金额:$13.0万
-
财政年份:2003
-
负责人:Gail-Joon Ahn
-
依托单位:
Exploratory Research-Scalable Token-Based Authentication: Architectures and Mechanisms
-
批准号:0124873
-
项目类别:Standard Grant
-
资助金额:$3.45万
-
财政年份:2001
-
负责人:Gail-Joon Ahn
-
依托单位:
海外基金