Systems for Computation on Encrypted Data
Systems for Computation on Encrypted Data
批准号:
RGPIN-2017-05849
负责人:
Kerschbaum, Florian
金额:
$3.64万
依托单位:
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2018
资助国家:
加拿大
项目状态:
已结题
起止时间:
2018-01-01 至 2019-12-31
中文摘要
失去控制,以及可能向服务提供商、恶意内部人士或有动机的黑客泄露私人信息,被视为广泛采用云计算的障碍。许多最新的加密科学发展,如同态和函数加密或安全多方计算,提供了一种可行的解决方案,即在将数据发送到云之前对数据进行加密。然而,现有的软件-绝大多数代码-太难用这些加密技术进行改造,也不能从理论上的进步中受益。*我将通过研究新的方法来克服这一挑战,这些方法保留了现有的编程接口和语言,如Java或SQL,但编译成运行在高度加密数据上的版本。来自系统社区的现有方法,如CryptDB或JCrypt,能够执行现有程序,但使用弱密码机制,例如确定性加密,而来自安全社区的现有方法,如动态对称可搜索加密或自动加密,使用可证明安全的方法,但严重缺乏功能,例如不允许范围查询。我的目标是在计算机科学中将这两种方法联系起来。一方面,我的目标是严格的形式化安全模型,清楚地捕获隐含的泄漏;另一方面,我的目标是工程上可测试的系统,这些系统可以实际和实验地验证理论上的性能收益。这需要在最先进的基础上取得以下进展:1)研究捕获预期功能和安全性的新的正式安全模型,2)为这些模型改进密码机制和系统算法,最后3)证明这些模型中的安全性和正确性。*我将针对重要的、已建立的编程接口,如SQL和Java,它们很难改变。对于SQL,我将开发没有泄漏的改进的可搜索加密方案和相应的正式模型,以捕获泄漏滥用攻击的影响(博士生1)。此外,我还将使用数据无关算法开发安全计算中的查询处理(硕士研究生#3)。对于Java,我将为可验证的同态计算开发改进的方法(博士生#2),并为恶意模型(硕士生#4)开发知识推理。我会将开发的方法集成到应用程序服务器和数据库中,以用于示范应用程序(硕士研究生#5)。*如果在提案结束时,我们拥有在云中基于加密数据运行现有的、现实世界的、大型的交互式应用程序的科学基础,我就已经成功了。拟议的工作对加拿大来说很有价值,因为它在计算机安全方面培训HQP,在一个非常活跃的研究领域展示了科学上的卓越,并旨在云计算领域取得高度工业相关性的突破。**
英文摘要
The loss of control and the potential disclosure of private information to the service provider, malicious insiders or motivated hackers are seen as a barrier to the wide-spread adoption of cloud computing. Many recent scientific developments in encryption, such as homomorphic and functional encryption or secure multi-party computation, offer a viable solution by encrypting the data before sending it to the cloud. However, existing software – the vast majority of code – is too difficult to retrofit with these encryption techniques and does not benefit from the theoretical advances.*******I will overcome this challenge by researching new methods that preserve existing programming interfaces and languages, such as Java or SQL, but compile to versions running on strongly encrypted data. Existing methods from the systems community, such as CryptDB or JCrypt, are capable to execute existing programs, but use weak cryptographic mechanisms, e.g. deterministic encryption, and existing methods from the security community, such as dynamic symmetric searchable encryption or AutoCrypt, use provably secure methods, but significantly lack in functionality, e.g. not allowing range queries. I aim to bridge those two approaches in computer science. On the one hand I aim at rigorous formal models of security clearly capturing the implied leakage and on the other hand I aim at engineering testable systems that can practically and experimentally verify the theoretical performance gains. This requires the following advances beyond the state-of-the-art: researching 1) new formal security models that capture the intended functionality and security, developing 2) improved cryptographic mechanisms and systems algorithms for these models and finally 3) proving security and correctness in these models.******I will target important, established programming interfaces, such as SQL and Java, which are very hard to change. For SQL I will develop improved searchable encryption schemes which have no leakage and corresponding formal models that capture the impact of leakage-abuse attacks (PhD student #1). Additionally I will develop query processing in secure computation using data-oblivious algorithms (Master student #3). For Java I will develop improved methods for verifiable homomorphic computation (PhD student #2) and develop knowledge inference for the malicious model (Master student #4). I will integrate the methods developed into application servers and databases for an exemplary application (Master student #5).******I will have been successful, if at the end of the proposal we have the scientific foundation to run existing, real-world, large, interactive applications in the cloud on encrypted data. The proposed work is of value to Canada by training HQP in computer security, demonstrating scientific excellence in a very active research field and aiming at a break-through of high industrial relevance in cloud computing.**
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
NSERC/RBC Associate Industrial Research Chair in Data Security
-
批准号:548635-2018
-
项目类别:Industrial Research Chairs
-
资助金额:$14.57万
-
财政年份:2021
-
负责人:Kerschbaum, Florian
-
依托单位:
Systems for Computation on Encrypted Data
-
批准号:RGPIN-2017-05849
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$7.29万
-
财政年份:2021
-
负责人:Kerschbaum, Florian
-
依托单位:
Systems for Computation on Encrypted Data
-
批准号:RGPIN-2017-05849
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$3.64万
-
财政年份:2020
-
负责人:Kerschbaum, Florian
-
依托单位:
NSERC/RBC Associate Industrial Research Chair in Data Security
-
批准号:548635-2018
-
项目类别:Industrial Research Chairs
-
资助金额:$14.57万
-
财政年份:2020
-
负责人:Kerschbaum, Florian
-
依托单位:
Privacy-respecting collaborative data analysis
-
批准号:531191-2018
-
项目类别:Collaborative Research and Development Grants
-
资助金额:$12.06万
-
财政年份:2020
-
负责人:Kerschbaum, Florian
-
依托单位:
Infrastructure for Privacy-Preserving Data Analysis
-
批准号:RTI-2021-00119
-
项目类别:Research Tools and Instruments
-
资助金额:$9.86万
-
财政年份:2020
-
负责人:Kerschbaum, Florian
-
依托单位:
NSERC/RBC Associate Industrial Research Chair in Data Security
-
批准号:548635-2018
-
项目类别:Industrial Research Chairs
-
资助金额:$14.57万
-
财政年份:2019
-
负责人:Kerschbaum, Florian
-
依托单位:
Systems for Computation on Encrypted Data
-
批准号:DGDND-2017-00085
-
项目类别:DND/NSERC Discovery Grant Supplement
-
资助金额:$2.91万
-
财政年份:2019
-
负责人:Kerschbaum, Florian
-
依托单位:
Systems for Computation on Encrypted Data
-
批准号:RGPIN-2017-05849
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$3.64万
-
财政年份:2019
-
负责人:Kerschbaum, Florian
-
依托单位:
Systems for Computation on Encrypted Data
-
批准号:507908-2017
-
项目类别:Discovery Grants Program - Accelerator Supplements
-
资助金额:$2.91万
-
财政年份:2019
-
负责人:Kerschbaum, Florian
-
依托单位:
Privacy-respecting collaborative data analysis
-
批准号:531191-2018
-
项目类别:Collaborative Research and Development Grants
-
资助金额:$12.06万
-
财政年份:2019
-
负责人:Kerschbaum, Florian
-
依托单位:
Systems for Computation on Encrypted Data
-
批准号:507908-2017
-
项目类别:Discovery Grants Program - Accelerator Supplements
-
资助金额:$2.91万
-
财政年份:2018
-
负责人:Kerschbaum, Florian
-
依托单位:
Systems for Computation on Encrypted Data
-
批准号:DGDND-2017-00085
-
项目类别:DND/NSERC Discovery Grant Supplement
-
资助金额:$2.91万
-
财政年份:2018
-
负责人:Kerschbaum, Florian
-
依托单位:
Privacy-respecting collaborative data analysis****
-
批准号:531191-2018
-
项目类别:Collaborative Research and Development Grants
-
资助金额:$12.06万
-
财政年份:2018
-
负责人:Kerschbaum, Florian
-
依托单位:
Systems for Computation on Encrypted Data
-
批准号:RGPIN-2017-05849
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$3.64万
-
财政年份:2017
-
负责人:Kerschbaum, Florian
-
依托单位:
Systems for Computation on Encrypted Data
-
批准号:DGDND-2017-00085
-
项目类别:DND/NSERC Discovery Grant Supplement
-
资助金额:$2.91万
-
财政年份:2017
-
负责人:Kerschbaum, Florian
-
依托单位:
Systems for Computation on Encrypted Data
-
批准号:507908-2017
-
项目类别:Discovery Grants Program - Accelerator Supplements
-
资助金额:$2.91万
-
财政年份:2017
-
负责人:Kerschbaum, Florian
-
依托单位:
国内基金
海外基金
基于分位数g-computation的多污染物联合空气质量健康指数构建及预测效果评价
-
批准号:--
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2022
-
负责人:李嘉琛
-
依托单位:
基于g-computation控制纵向数据未测混杂因素的因果推断模型构建及应用研究
-
批准号:81903416
-
项目类别:青年科学基金项目
-
资助金额:19.0万元
-
批准年份:2019
-
负责人:陈永杰
-
依托单位: