Strengthening the Foundations of Access Control
Strengthening the Foundations of Access Control
批准号:
RGPIN-2014-06716
负责人:
Tripunitara, Mahesh
金额:
$2.84万
依托单位:
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2015
资助国家:
加拿大
项目状态:
已结题
起止时间:
2015-01-01 至 2016-12-31
中文摘要
访问控制包括一些技术和机制,通过这些技术和机制,我们可以确保只有授权的主体才能对资源执行某些操作,例如读和写。它是已部署系统安全的重要组成部分,也是一个活跃的研究领域。从过去几年PI的经验,包括与业界的合作研究,他了解到访问控制的基础需要大量的工作。这是这项提案的重点。这项拟议的研究符合PI的长期愿景,即尽可能使计算机系统尽可能安全,我们所有人都越来越依赖计算机系统来满足我们的基本需求。
国际和平研究所建议解决三个基本问题。一种是取证,我们用它来回答关于系统过去状态的问题。取证很重要,因为预防性安全技术经常失败。访问控制系统是进行法医分析的重要环境;然而,在以前的研究中,法医分析问题并没有被提出。PI建议在访问控制的背景下准确地提出和调查广泛类别的法医分析问题。这项工作的结果之一将是目标导向的日志记录,因此只维护有助于高效分析的基本日志。PI建议研究的第二个主题是授权策略的保密性。授权策略本身就是需要保护的资源,因为它们的某些部分(例如,用户是否具有特定特权)可能对泄露敏感。在这种情况下,PI建议回答的中心问题是:某些授权策略是否天生就比其他策略更具保密性和弹性?PI建议发展一种具有直观吸引力的保密韧性的概念,并探索几个研究方向,例如是否有可能在不改变策略的有效授权的情况下增加其保密韧性,以及是否可以构建具有期望的保密韧性的基于角色的访问控制(RBAC)策略。PI建议研究的第三个主题是测试授权和访问控制系统实现的基础。最近,国际和平研究所与业界合作伙伴就这一问题开展了一些工作。在这方面,国际和平研究所建议解决几个研究问题。一个是识别和开发适当的语法和相关语义,以表示用于测试目的的授权系统以及我们想要测试的属性。另一种是将这样的声明性属性与过程跟踪相关联的理论,这些跟踪的实例将在被测试的系统上执行。PI还建议开发使用模型检查器等现有工具自动生成跟踪实例的技术,并将其与执行跟踪实例的过程捆绑在一起。所有这些工作都将为现实世界的授权和访问控制系统带来一个完整的测试生态系统。
拟议的研究对加拿大有价值,并将补充PI的其他研究,包括他与行业合作伙伴合作进行的研究。它将在三个方面产生高度影响。它将在重要的计算机安全领域培训高素质的人员(HQP),它将在有声望的和有选择性的期刊和会议上发表高质量的研究论文,这反过来将使研究生对更大的研究社区有宝贵的接触,它将为PI和其他研究人员提供更多的途径,通过将拟议的工作应用于他们的现实世界问题,与加拿大的行业合作伙伴形成研究合作。
英文摘要
Access control comprises the techniques and mechanisms by which we ensure that only authorized principals are able to perform certain actions, such as read and write, on resources. It is an essential component of the security of deployed systems, and is also an active area of research. From the PI's experience over the past few years, which includes collaborative research with industry, he has learned that the foundations of access control need considerable work. This is the focus of this proposal. The proposed research fits into the PI's longer term vision of making computer systems, on which all of us increasingly rely for even our basic needs, as secure as is feasible.
The PI proposes to address three fundamental topics. One is forensics, with which we answer questions about past states of a system. Forensics is important because preventive security techniques often fail. Access control systems are an important context in which to perform forensic analysis; however, the forensic analysis problem has not been posed as such in prior research. The PI proposes to precisely pose and investigate a broad class of forensic analysis problems in the context of access control. One of the outcomes of this work will be goal-directed logging, so only essential logs are maintained that lend to efficient analysis. A second topic that the PI proposes to research is the secrecy resilience of authorization policies. Authorization policies are themselves resources that need to be protected because portions of them (e.g., whether a user has a certain privilege) may be sensitive to disclosure. The central question that the PI proposes to answer in this context is: are some authorization policies inherently more secrecy resilient than others? The PI proposes to evolve a notion of secrecy resilience that has intuitive appeal, and explore several research directions, such as whether it is possible to increase the secrecy resilience of a policy without changing its effective authorizations, and whether one can build Role-Based Access Control (RBAC) policies that have a desired secrecy resilience. The third topic that the PI proposes to research is the foundations of testing implementations of authorization and access control systems. This is a topic on which the PI has conducted some recent work in collaboration with industry partners. There are several research problems that the PI proposes to address in this context. One is the identification and development of an appropriate syntax and associated semantics to express authorization systems for the purpose of testing, and the properties for which we would like to test. Another is a theory that relates such declarative properties with procedural traces, instances of which are to be exercised on the system under test. The PI proposes also to develop techniques for automatically generating trace instances using existing tools such as model checkers, and tying that to the process of exercising the trace instances. All of this work will result in a complete testing ecosystem for real world authorization and access control systems.
The proposed research is of value to Canada, and will complement the PI's other research, including those he performs in collaboration with industry partners. It will be high-impact in three ways. It will train Highly Qualified Personnel (HQP) in the important area of computer security, it will result in high-quality research publications in prestigious and selective journals and conferences, which in turn will give graduate students valuable exposure to the larger research community, and it will provide the PI and other researchers greater avenues to form research collaborations with Canadian industry partners by way of applying the proposed work to their real world problems.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Trust, in an Internet of Things
-
批准号:RGPIN-2019-05634
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.04万
-
财政年份:2022
-
负责人:Tripunitara, Mahesh
-
依托单位:
Trust, in an Internet of Things
-
批准号:RGPIN-2019-05634
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.04万
-
财政年份:2021
-
负责人:Tripunitara, Mahesh
-
依托单位:
Software Dependability for 5G Systems
-
批准号:532264-2018
-
项目类别:Collaborative Research and Development Grants
-
资助金额:$9.98万
-
财政年份:2021
-
负责人:Tripunitara, Mahesh
-
依托单位:
Software Dependability for 5G Systems
-
批准号:532264-2018
-
项目类别:Collaborative Research and Development Grants
-
资助金额:$10.2万
-
财政年份:2020
-
负责人:Tripunitara, Mahesh
-
依托单位:
Trust, in an Internet of Things
-
批准号:RGPIN-2019-05634
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.04万
-
财政年份:2020
-
负责人:Tripunitara, Mahesh
-
依托单位:
Software Dependability for 5G Systems
-
批准号:532264-2018
-
项目类别:Collaborative Research and Development Grants
-
资助金额:$10.05万
-
财政年份:2019
-
负责人:Tripunitara, Mahesh
-
依托单位:
Trust, in an Internet of Things
-
批准号:RGPIN-2019-05634
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.04万
-
财政年份:2019
-
负责人:Tripunitara, Mahesh
-
依托单位:
Strengthening the Foundations of Access Control
-
批准号:RGPIN-2014-06716
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.84万
-
财政年份:2018
-
负责人:Tripunitara, Mahesh
-
依托单位:
Software Dependability for 5G Systems**********
-
批准号:532264-2018
-
项目类别:Collaborative Research and Development Grants
-
资助金额:$6.7万
-
财政年份:2018
-
负责人:Tripunitara, Mahesh
-
依托单位:
Automated Security Testing of an Electronic Asset Transfer Platform
-
批准号:516011-2017
-
项目类别:Engage Grants Program
-
资助金额:$1.82万
-
财政年份:2017
-
负责人:Tripunitara, Mahesh
-
依托单位:
Strengthening the Foundations of Access Control
-
批准号:RGPIN-2014-06716
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.84万
-
财政年份:2017
-
负责人:Tripunitara, Mahesh
-
依托单位:
Strengthening the Foundations of Access Control
-
批准号:RGPIN-2014-06716
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.84万
-
财政年份:2016
-
负责人:Tripunitara, Mahesh
-
依托单位:
Strengthening the Foundations of Access Control
-
批准号:RGPIN-2014-06716
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.84万
-
财政年份:2014
-
负责人:Tripunitara, Mahesh
-
依托单位:
Prudent use of Dynamic Random Access Memory (DRAM) cells in security sensitive applications
-
批准号:458433-2013
-
项目类别:Engage Grants Program
-
资助金额:$1.82万
-
财政年份:2013
-
负责人:Tripunitara, Mahesh
-
依托单位:
Security testing a collaboration application based on an email-like paradigm
-
批准号:454256-2013
-
项目类别:Engage Grants Program
-
资助金额:$1.82万
-
财政年份:2013
-
负责人:Tripunitara, Mahesh
-
依托单位:
Realizing policy verification subsystems for access control systems
-
批准号:372187-2009
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.48万
-
财政年份:2013
-
负责人:Tripunitara, Mahesh
-
依托单位:
Realizing policy verification subsystems for access control systems
-
批准号:372187-2009
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.48万
-
财政年份:2012
-
负责人:Tripunitara, Mahesh
-
依托单位:
New user-provider interactions in identity management systems
-
批准号:442652-2012
-
项目类别:Engage Grants Program
-
资助金额:$1.82万
-
财政年份:2012
-
负责人:Tripunitara, Mahesh
-
依托单位:
Realizing policy verification subsystems for access control systems
-
批准号:372187-2009
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.48万
-
财政年份:2011
-
负责人:Tripunitara, Mahesh
-
依托单位:
Monitoring low-bandwidth network traffic for security in enterprise settings
-
批准号:421877-2011
-
项目类别:Engage Grants Program
-
资助金额:$1.82万
-
财政年份:2011
-
负责人:Tripunitara, Mahesh
-
依托单位:
海外基金