Collaborative Research: CICI: Secure and Resilient Architecture: Data Integrity Assurance and Privacy Protection Solutions for Secure Interoperability of Cloud Resources

合作研究:CICI:安全和弹性架构:云资源安全互操作性的数据完整性保证和隐私保护解决方案

基本信息

  • 批准号:
    1642078
  • 负责人:
  • 金额:
    $ 22.46万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Standard Grant
  • 财政年份:
    2016
  • 资助国家:
    美国
  • 起止时间:
    2016-10-01 至 2022-09-30
  • 项目状态:
    已结题

项目摘要

Cloud computing provides many clear benefits for users, including scalability and reduced system acquisition cost. However, data security, integrity and privacy are becoming major concerns for scientific researchers when they access data from the cloud to conduct experiments or analytics. In addition, data owners may not want to reveal their data to cloud service providers either because of the sensitivity of the data (e.g., medical records) or because of its value. Therefore, it is important to create cloud data integrity assurance and privacy protection solutions that help users fully embrace cloud services as well as protect cyberinfrastructure resources. With a cloud database, data owners can store large‐scale datasets collected from various sources. Users can then launch queries retrieving the data records for conducting research and experiments. However, there are several possible threats to query result accuracy. For example, a cloud database could be compromised and the stored data could be tampered with. There could be a malfunction in the cloud server, so that the cloud database inadvertently returns incomplete query results. It is unlikely that the client would be aware of such incorrect or incomplete query results. Consequently, erroneous data could be employed in subsequent scientific experiments or analyses, which could lead to false results. Cloud database query integrity assurance is critical issue that underpins a secure and trustworthy end‐to‐end scientific workflow. This work approaches these problems in a privacy‐friendly manner, building on top of encrypted queries over encrypted data. This is key for achieving both data privacy and data integrity. Data provenance - the history of the data and how its been handled - is also an important aspect of scientific workflows. However, securing the provenance to provide integrity, privacy, and confidentiality guarantees is also challenging, making it hard for many scientific workflows to provide a verifiable provenance history of scientific data and query results. With clouds, providing such guarantees is difficult for both data and provenance. This project enables infrastructural support for secure collection, storage, transmission, and verification of provenance information for all data and results stored and computed in the cloud. The availability of such verifiable provenance offers benefits to scientific workflows, making the process more trustworthy via verifiable history and results. The research team creates a query integrity assurance, data privacy protection, and verifiable provenance framework which provides an array of solutions for supporting secure cloud services. This project contributes to the cybersecurity research community by piloting novel cloud data security approaches that accomplish the following goals: (1) developing Voronoi diagram‐based integrity assurance techniques, (2) designing cloud database data privacy protection methods, (3) modeling the trade off between query integrity assurance and query evaluation costs, (4) realizing secure cloud data provenance mechanisms, and (5) implementing a prototype system, where all the components are integrated for security and performance evaluation.
云计算为用户提供了许多明显的好处,包括可扩展性和降低系统购置成本。然而,当科学研究人员从云端访问数据进行实验或分析时,数据安全、完整性和隐私正成为他们关注的主要问题。此外,由于数据(例如医疗记录)的敏感性或其价值,数据所有者可能不想向云服务提供商透露其数据。因此,创建云数据完整性保证和隐私保护解决方案,帮助用户充分拥抱云服务并保护网络基础设施资源非常重要。通过云数据库,数据所有者可以存储从各种来源收集的大规模数据集。然后,用户可以启动查询来检索数据记录以进行研究和实验。然而,查询结果的准确性可能存在多种威胁。例如,云数据库可能会受到损害,存储的数据可能会被篡改。云服务器可能出现故障,导致云数据库无意中返回不完整的查询结果。客户端不太可能知道这种不正确或不完整的查询结果。因此,错误的数据可能会被用于后续的科学实验或分析,从而导致错误的结果。云数据库查询完整性保证是支撑安全且值得信赖的端到端科学工作流程的关键问题。这项工作以隐私友好的方式解决这些问题,建立在加密数据的加密查询之上。这是实现数据隐私和数据完整性的关键。数据来源——数据的历史及其处理方式——也是科学工作流程的一个重要方面。然而,确保来源以提供完整性、隐私和机密性保证也具有挑战性,这使得许多科学工作流程很难提供科学数据和查询结果的可验证来源历史。对于云来说,提供这样的保证对于数据和来源来说都是困难的。该项目为云中存储和计算的所有数据和结果的来源信息的安全收集、存储、传输和验证提供基础设施支持。这种可验证来源的可用性为科学工作流程带来了好处,通过可验证的历史和结果使该过程更加值得信赖。研究团队创建了查询完整性保证、数据隐私保护和可验证来源框架,为支持安全云服务提供了一系列解决方案。该项目通过试点新颖的云数据安全方法来为网络安全研究社区做出贡献,这些方法可实现以下目标:(1) 开发基于 Voronoi 图的完整性保证技术,(2) 设计云数据库数据隐私保护方法,(3) 建模查询完整性保证和查询评估成本之间的权衡,(4)实现安全的云数据来源机制,以及(5)实现原型系统,其中集成了所有组件以进行安全性和性能评估。

项目成果

期刊论文数量(16)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
AVGuard: A Forensic Investigation Framework for Autonomous Vehicles
AVGuard:自动驾驶汽车取证调查框架
Towards Strengthening the Security of Healthcare Devices using Secure Configuration Provenance
使用安全配置来源加强医疗设备的安全性
IoTaaS: Drone-Based Internet of Things as a Service Framework for Smart Cities
IoTaaS:基于无人机的物联网作为智慧城市的服务框架
  • DOI:
    10.1109/jiot.2021.3137362
  • 发表时间:
    2022-07
  • 期刊:
  • 影响因子:
    10.6
  • 作者:
    Hoque, Mohammad Aminul;Hossain, Mahmud;Noor, Shahid;Islam, S. M.;Hasan, Ragib
  • 通讯作者:
    Hasan, Ragib
Towards a Threat Model for Vehicular Fog Computing
A Trust Management Framework for Connected Autonomous Vehicles Using Interaction Provenance
使用交互来源的联网自动驾驶车辆的信任管理框架
{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Ragib Hasan其他文献

TOWARDS A CLOUD-BASED APPROACH FOR SPAM URL DEDUPLICATION FOR BIG DATASETS
针对大数据集的垃圾邮件 URL 重复数据删除的基于云的方法
  • DOI:
    10.29268/stcc.2014.0008
  • 发表时间:
    2014-07-01
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Shams Zawoad;Ragib Hasan;Gary Warner;Munirul M. Haque
  • 通讯作者:
    Munirul M. Haque
Phish-Net: Investigating phish clusters using drop email addresses
Phish-Net:使用丢弃电子邮件地址调查网络钓鱼集群
  • DOI:
    10.1109/ecrs.2013.6805777
  • 发表时间:
    2013-09-01
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Shams Zawoad;A. Dutta;A. Sprague;Ragib Hasan;Jason Britt;Gary Warner
  • 通讯作者:
    Gary Warner
Bepari: A Cost-aware Comprehensive Agent Architecture for Opaque Cloud Services
Bepari:用于不透明云服务的成本感知综合代理架构
FAPA: flooding attack protection architecture in a cloud system
FAPA:云系统中的洪泛攻击防护架构
  • DOI:
    10.1504/ijcc.2014.066790
  • 发表时间:
    2024-09-14
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Kazi Zunnurhain;Susan V. Vrbsky;Ragib Hasan
  • 通讯作者:
    Ragib Hasan
A Trustworthy Cloud Forensics Environment
值得信赖的云取证环境
  • DOI:
    10.1007/978-3-319-24123-4_16
  • 发表时间:
    2015-01-26
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Shams Zawoad;Ragib Hasan
  • 通讯作者:
    Ragib Hasan

Ragib Hasan的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Ragib Hasan', 18)}}的其他基金

CyberCorps Scholarship for Service (Renewal): Cybersecurity meets Artificial Intelligence for preparing the Next Generation of Cybersecurity Professionals
Cyber​​Corps 服务奖学金(续展):网络安全与人工智能的结合,为下一代网络安全专业人员做好准备
  • 批准号:
    2234868
  • 财政年份:
    2023
  • 资助金额:
    $ 22.46万
  • 项目类别:
    Continuing Grant
SCC-PG: StreetBit: A Bluetooth beacon based System for Alerting Distracted Pedestrians in Urban Environments
SCC-PG:StreetBit:基于蓝牙信标的系统,用于警告城市环境中分心的行人
  • 批准号:
    1952090
  • 财政年份:
    2020
  • 资助金额:
    $ 22.46万
  • 项目类别:
    Standard Grant
SaTC: EDU: Digital Forensics Education for Judicial Officials
SaTC:EDU:司法官员数字取证教育
  • 批准号:
    1723768
  • 财政年份:
    2017
  • 资助金额:
    $ 22.46万
  • 项目类别:
    Standard Grant
CAREER: Secure and Trustworthy Provenance for Accountable Clouds
职业:负责任的云的安全且值得信赖的来源
  • 批准号:
    1351038
  • 财政年份:
    2014
  • 资助金额:
    $ 22.46万
  • 项目类别:
    Continuing Grant

相似国自然基金

IGF-1R调控HIF-1α促进Th17细胞分化在甲状腺眼病发病中的机制研究
  • 批准号:
    82301258
  • 批准年份:
    2023
  • 资助金额:
    30 万元
  • 项目类别:
    青年科学基金项目
CTCFL调控IL-10抑制CD4+CTL旁观者激活促口腔鳞状细胞癌新辅助免疫治疗抵抗机制研究
  • 批准号:
    82373325
  • 批准年份:
    2023
  • 资助金额:
    49 万元
  • 项目类别:
    面上项目
RNA剪接因子PRPF31突变导致人视网膜色素变性的机制研究
  • 批准号:
    82301216
  • 批准年份:
    2023
  • 资助金额:
    30 万元
  • 项目类别:
    青年科学基金项目
血管内皮细胞通过E2F1/NF-kB/IL-6轴调控巨噬细胞活化在眼眶静脉畸形中的作用及机制研究
  • 批准号:
    82301257
  • 批准年份:
    2023
  • 资助金额:
    30 万元
  • 项目类别:
    青年科学基金项目
基于多元原子间相互作用的铝合金基体团簇调控与强化机制研究
  • 批准号:
    52371115
  • 批准年份:
    2023
  • 资助金额:
    50 万元
  • 项目类别:
    面上项目

相似海外基金

CICI:TCR: Enhancing Security and Privacy of Community Cyberinfrastructures for Collaborative Research
CICI:TCR:增强社区网络基础设施的安全性和隐私性以进行协作研究
  • 批准号:
    2319988
  • 财政年份:
    2023
  • 资助金额:
    $ 22.46万
  • 项目类别:
    Standard Grant
Collaborative Research: CICI: Secure and Resilient Architecture: SciGuard: Building a Security Architecture for Science DMZ Based on SDN and NFV Technologies
合作研究:CICI:安全和弹性架构:SciGuard:基于SDN和NFV技术构建科学DMZ安全架构
  • 批准号:
    2128607
  • 财政年份:
    2021
  • 资助金额:
    $ 22.46万
  • 项目类别:
    Standard Grant
Collaborative Research: CICI: Secure and Resilient Architecture: SciGuard: Building a Security Architecture for Science DMZ Based on SDN and NFV Technologies
合作研究:CICI:安全和弹性架构:SciGuard:基于SDN和NFV技术构建科学DMZ安全架构
  • 批准号:
    2128607
  • 财政年份:
    2021
  • 资助金额:
    $ 22.46万
  • 项目类别:
    Standard Grant
Collaborative Research: CICI: Secure and Resilient Architecture: SciGuard: Building a Security Architecture for Science DMZ Based on SDN and NFV Technologies
合作研究:CICI:安全和弹性架构:SciGuard:基于SDN和NFV技术构建科学DMZ安全架构
  • 批准号:
    1642143
  • 财政年份:
    2017
  • 资助金额:
    $ 22.46万
  • 项目类别:
    Standard Grant
Collaborative Research: CICI: Regional: SouthEast SciEntific Cybersecurity for University Research (SouthEast SECURE)
合作研究:CICI:区域:东南大学研究科学网络安全 (SouthEast SECURE)
  • 批准号:
    1812404
  • 财政年份:
    2017
  • 资助金额:
    $ 22.46万
  • 项目类别:
    Standard Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了