SaTC: CORE: Small: Automatic Detection and Repair of Side Channel Vulnerabilities in Software Code
SaTC: CORE: Small: Automatic Detection and Repair of Side Channel Vulnerabilities in Software Code
批准号:
2245344
负责人:
Jakub Szefer
金额:
$60.0万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2023
资助国家:
美国
项目状态:
未结题
起止时间:
2023-07-01 至 2026-06-30
中文摘要
在密码学领域,侧信道是指可以通过预期输出以外的方式从密码系统中获得的任何信息。在加密算法执行过程中,由于系统功耗随处理的保密数据不同而变化,会产生功率和电磁侧信道漏洞,可能会在不经意间泄露敏感信息。恒功率技术用于防止敏感信息通过功率侧通道泄漏。然而,即使对密码学专家来说,编写这样的代码也是一项挑战。为此,该项目有助于推动开发无功率和电磁侧信道代码的最新技术。该项目的新颖之处在于,它开发了自动化的方法来帮助软件编写人员,包括非专家,在他们的代码中找到电源和电磁侧信道漏洞的潜在位置。此外,该研究还开发了在代码中发现潜在问题后修复代码的方法。该项目更广泛的意义和重要性在于设计和实现保护关键用户数据和代码免受可能用于泄露有价值或私人数据的侧信道攻击的方法和框架。该项目创建了将动态分析与符号分析技术相结合的方法和工具,以识别软件代码中最脆弱的位置。动态分析技术包括动态污染跟踪和随机测试,而符号分析技术包括关系或微分符号执行、可满足性和优化模理论以及模型计数。该项目开发的工具和算法利用了Hamming权重和距离泄漏模型。这些模型依赖于这样一个事实,即在处理敏感数据时,系统的功耗取决于寄存器的位翻转。因此,这些方法开发了新的寄存器分析技术,使用动态和符号执行低级代码,如二进制或中间表示。在符号分析中,该方法在每个保存与正在处理的敏感数据相关的值的中间变量或寄存器中派生出这种现象的形式化表示。此外,该项目开发了使用语法指导的合成方法修复易受攻击的代码位置的新方法。它还依赖于汉明权重泄漏模型和代码的符号分析,以及对实际硬件的测试向量泄漏评估来接受或拒绝候选修复。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
In the field of cryptography, a side-channel refers to any information that can be obtained from a cryptographic system through means other than the expected output. Power and electromagnetic side-channel vulnerabilities occur during the execution of the cryptographic algorithm when the power consumption of the system varies depending on the secret data being processed, which can inadvertently reveal sensitive information. Constant-power techniques are used to prevent the leakage of sensitive information through power side-channels. However, writing such code is challenging even for expert cryptographers. To this end, this project helps advance the state-of-the-art in developing code free of power and electromagnetic side channels. The project’s novelties are in that it develops automated methods to assist software writers, including non-experts, in finding potential locations of the power and electromagnetic side-channel vulnerabilities in their code. Additionally, the research develops methods to repair the code after a potential problem in the code has been identified. The project's broader significance and importance lie in the design and realization of methods and frameworks to protect critical user data and code from side-channel attacks that could be used to leak valuable or private data.The project creates methods and tools that combine dynamic analysis with symbolic analysis techniques to identify the most vulnerable locations in software code. Dynamic analysis techniques involve dynamic taint tracking and random testing, while symbolic analysis techniques include relational or differential symbolic execution, satisfiability and optimization modulo theories, and model counting. The tools and algorithms developed in the project leverage the Hamming weight and distance leakage models. These models rely on the fact that power consumption of the system varies depending on bit flips at registers while sensitive data is being processed. Therefore, the methods develop new register analysis techniques that use dynamic and symbolic execution of low-level code, such as binaries or intermediate representations. In symbolic analysis, the method derives a formal representation of this phenomenon at each intermediate variable or register that holds values related to sensitive data being processed. Additionally, this project develops new methods to repair vulnerable code locations using a syntax-guided synthesis approach. It also relies on the Hamming weight leakage model and symbolic analysis of code, as well as test-vector leakage assessment on real hardware to accept or reject candidate repairs.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SaTC: CORE: Medium: Collaborative: Security of Reconfigurable Cloud Computing
-
批准号:1901901
-
项目类别:Standard Grant
-
资助金额:$45.72万
-
财政年份:2019
-
负责人:Jakub Szefer
-
依托单位:
SaTC: STARSS: Small: Collaborative: Design and Security Verification of Next-Generation Open-Source Processors
-
批准号:1813797
-
项目类别:Standard Grant
-
资助金额:$16.56万
-
财政年份:2018
-
负责人:Jakub Szefer
-
依托单位:
CAREER: Security Applications of DRAM Cell Decay Effects
-
批准号:1651945
-
项目类别:Continuing Grant
-
资助金额:$55.0万
-
财政年份:2017
-
负责人:Jakub Szefer
-
依托单位:
SaTC: CORE: Small: Collaborative: Hardware Architectures for Post-Quantum Cryptography
-
批准号:1716541
-
项目类别:Standard Grant
-
资助金额:$25.2万
-
财政年份:2017
-
负责人:Jakub Szefer
-
依托单位:
STARSS: Small: Collaborative: Practical and Scalable Security Verification of Security-Aware Hardware Architectures
-
批准号:1524680
-
项目类别:Standard Grant
-
资助金额:$16.67万
-
财政年份:2015
-
负责人:Jakub Szefer
-
依托单位:
CSR: Small: Split Virtual Machine Execution for Reliability and Security
-
批准号:1419869
-
项目类别:Standard Grant
-
资助金额:$20.08万
-
财政年份:2014
-
负责人:Jakub Szefer
-
依托单位:
国内基金
海外基金
登录
查看更多内容
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
-
批准号:82371765
-
项目类别:面上项目
-
资助金额:50万元
-
批准年份:2023
-
负责人:谭广云
-
依托单位:
锕系元素5f-in-core的GTH赝势和基组的开发
-
批准号:22303037
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2023
-
负责人:鲁俊波
-
依托单位:
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
-
批准号:--
-
项目类别:--
-
资助金额:52万元
-
批准年份:2022
-
负责人:孙丙军
-
依托单位:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
-
批准号:--
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2022
-
负责人:叶成林
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:--
-
项目类别:--
-
资助金额:55万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:82072415
-
项目类别:面上项目
-
资助金额:55.0万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
肌营养不良蛋白聚糖Core M3型甘露糖肽的精确制备及功能探索
-
批准号:92053110
-
项目类别:重大研究计划
-
资助金额:70.0万元
-
批准年份:2020
-
负责人:彭鹏
-
依托单位:
Core-1-O型聚糖黏蛋白缺陷诱导胃炎发生并介导慢性胃炎向胃癌转化的分子机制研究
-
批准号:81902805
-
项目类别:青年科学基金项目
-
资助金额:20.5万元
-
批准年份:2019
-
负责人:刘菲
-
依托单位:
原始地球增生晚期的Core-merging大碰撞事件:地核增生、核幔平衡与核幔边界结构的新认识
-
批准号:41973063
-
项目类别:面上项目
-
资助金额:65.0万元
-
批准年份:2019
-
负责人:周游
-
依托单位:
CORDEX-CORE区域气候模拟与预估研讨会
-
批准号:41981240365
-
项目类别:国际(地区)合作与交流项目
-
资助金额:1.5万元
-
批准年份:2019
-
负责人:陈威霖
-
依托单位: