课题基金 / 基金详情

PRIMaTE: PRIvacy preserving Multi-compartment Trusted Execution

PRIMaTE: PRIvacy preserving Multi-compartment Trusted Execution
PRMaTE:隐私保护多隔室可信执行
批准号:
391790956
负责人:
Professor Dr.-Ing. Rüdiger Kapitza
金额:
$0.0万
依托单位:
依托单位国家:
德国
项目类别:
Research Grants
财政年份:
2017
资助国家:
德国
项目状态:
已结题
起止时间:
2016-12-31 至 2022-12-31

项目摘要

项目成果

Professor Dr.-Ing. Rüdiger Kapitza的其他基金

相似基金

相关文献

中文摘要
翻译
如今,各种各样的在线服务(例如,网络搜索引擎、基于位置的服务、推荐系统)每天被数十亿用户使用。这些服务成功的关键是其结果的个性化,即向每个用户返回更接近她的结果兴趣。例如,给定由两个不同用户发送的web搜索查询,搜索引擎通常对搜索结果进行不同排名以最佳地适合每个用户偏好。但是,根据底层应用程序,用户配置文件可能包含有关最终用户的敏感信息。在这种情况下,迫切需要设计一种机制,使用户能够安全地访问在线服务,而不必担心他们的数据会从存储和处理数据的云平台泄露出去。拟议的PRIMaTE项目解决在线服务中的隐私保护问题。我们提出了一个系统,减少和精确指定的信任假设,同时仍然提供改进的性能相比,最先进的。我们的主要贡献将是系统地分解这些服务在强有力的硬件安全的车厢,在那里他们每个人都只能访问基本上必要的数据来执行分配的任务。在安全漏洞的情况下,例如由于攻击者利用一个甚至多个隔间的代码中的弱点,泄漏数据的影响将被限制在一定范围内,并且可以精确量化其影响。因此,攻击者可能只了解配置文件的某些方面,但无法将其链接到用户。PRIMATE通过利用最近的商品处理器(如2016年推出的Skylake一代英特尔处理器)提供的新型可信执行来实现这一目标。英特尔Software Guard Extensions(SGX)提供的可信执行是一项颠覆性技术,将影响未来代码和数据的保护方式。PRIMATE将利用可信执行来设计新颖的隐私保护在线服务。虽然目前对可信执行的研究集中在部署整个遗留应用程序(如在单个可信执行环境(TEE)中的数据库)或将现有应用程序分为两个部分(可信和不可信)的临时解决方案上,但PRIMaTE的目标是更系统化和细粒度的方法。它的目标是开发一种方法,将隐私保护在线服务分成多个相互作用的隔间,每个隔间由TEE实现。因此,每个TEE应处理尽可能少的数据,并具有定制的且因此最小的可信计算基础。虽然后者使得很难利用PRIMATE TEE,但如果攻击者能够成功闯入TEE,则前者限制了暴露的信息。
英文摘要
Nowadays, a wide variety of online services (e.g., web search engines, location-based services, recommender systems) are being used by billions of users on a daily basis.Key to the success of these services is the personalisation of their results, that is returning to each user those results that are closer to her interests. For instance, given a web search query sent by two different users, search engines generally rank differently the search results to best fit each user preferences. However, according to the underlying application, user profiles maycontain sensitive information about end users. In this context, it becomes urgent to devise mechanisms that allow users to securely access online services without fearing that their data will be leaked out from the cloud platforms where it is being stored and processed. The proposed PRIMaTE project addresses privacy-preserving in online services. We propose a system that reduces and precisely specifies trust assumptions, while still providing improved performance compared to the state of the art. Our key contribution will be to systematically decompose these services in strongly hardware-secured compartments, where each them has only access to the essentially necessary data to perform the assigned task. In case of security breaches for example due to attackers exploiting a weakness in the code of one or even multiple compartments, the impact of the leaked data will be kept at bounds and their effect can be precisely quantified. Thus, the attacker might only learn certain aspects of a profile butcannot link it to a user. PRIMaTE achieves this goal by utilizing novel trusted execution supportoffered by recent commodity processors such as the 2016 introduced Skylake generation of Intel processors. Trusted execution as offered by Intel Software Guard Extensions (SGX) is a disruptive technology that will impact how code and data is protected in the future. PRIMaTE will utilize trusted execution to devise novel privacy-preserving online services. While current research on trusted execution focused either on deploying whole legacy applications such as a databases in a single Trusted Execution Environment (TEE) or on ad-hoc solutions to split existing applications into two parts - a trusted and untrusted one - PRIMaTE aims for a more systematic and fine-grained approach. It targets to develop a methodology to split privacy-preserving online services into multiple interacting compartments each implemented by a TEE. Thereby, each TEE should handle as little data as possible and have a tailored and therefore minimal trusted computing base. While the latter makes it hard to exploit a PRIMaTE TEE, the former limits the exposed information if an attacker is able to successfully break into a TEE.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Scalable hardware-aided trusted data management
Resource efficient dynamic agreement and replication
Run-time environment for resource-scarce networked systems
Dependability Aspects in Configurable Embedded Operating Systems -- DanceOS
  • 批准号:
    182168484
  • 项目类别:
    Priority Programmes
  • 资助金额:
    $0.0万
  • 财政年份:
    2010
  • 负责人:
    Professor Dr.-Ing. Rüdiger Kapitza
  • 依托单位:
海外基金