Collaborative Research: SaTC: TTP: Medium: Toward Complete, User-Friendly, and Trustworthy Confidential Computing with Gramine
协作研究:SaTC:TTP:中:使用 Gramine 实现完整、用户友好且值得信赖的机密计算
基本信息
- 批准号:2244937
- 负责人:
- 金额:$ 59.84万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2023
- 资助国家:美国
- 起止时间:2023-07-01 至 2027-06-30
- 项目状态:未结题
- 来源:
- 关键词:
项目摘要
This project aims to mature Gramine, previously known as Graphene or Graphene-SGX, from a successful, open-source (LGPL v3.0) research prototype into a robust, easy-to-use, and trustworthy building block for confidential computing applications. Confidential computing protects code and data in use, building upon recent hardware trusted execution environments (TEEs), such as Intel's SGX enclaves. Confidential computing is essential for cloud computing applications that use sensitive data, such as health applications, where one must balance the economic benefits of cloud computing with regulatory compliance or other security concerns. Gramine is a "lift-and-shift" framework for running unmodified applications in Intel SGX. The project addresses various barriers to adopting Gramine in production settings, including challenges in compatibility, usability, and security of Gramine. The project's novelties are creating a robust, general-purpose, open-source, Linux-compatibility layer that can easily migrate legacy application code from one platform to another---here, emerging confidential computing hardware. The project's broader significance and importance is to accelerate the study of confidential computing and other emerging computational platforms. Gramine is already a building block for over 100 academic papers and several commercial product prototypes. Gramine is publicly available at https://github.com/gramineproject/gramine.The project focuses on three aspects of Gramine development. First, the project expands the set of system interfaces and applications that work on Gramine, with the goal of supporting 90% of the applications installed on a representative Debian/Ubuntu system. Second, the project improves the Gramine user experience, by addressing deployment issues, simplifying configuration and policy decisions, better integrating with other software frameworks, and expanding the set of supported TEEs. Third, the project improves the trustworthiness of Gramine's code base with advanced testing and analysis, as well as rewriting critical code in Rust programming language.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
该项目旨在从成功的开源(LGPL V3.0)研究原型中成熟的Gramine,以前称为石墨烯或石墨烯SGX,以作为机密计算应用程序的强大,易于使用且值得信赖的构建块。 机密计算保护使用中的代码和数据,建立在最新的硬件可信执行环境(TEE)的基础上,例如Intel的SGX Enclaves。机密计算对于使用敏感数据(例如健康应用程序)的云计算应用程序至关重要,在这种应用程序中,必须平衡云计算的经济利益与监管合规性或其他安全问题。 Gramine是用于在Intel SGX中运行未修改应用程序的“提升和转移”框架。 该项目涉及在生产环境中采用Gramine的各种障碍,包括兼容性,可用性和Gramine安全性的挑战。 该项目的新颖性正在创建一个强大的,通用的,开源的,开源的,Linux兼容的层,可以轻松地将旧版应用程序代码从一个平台迁移到另一个平台到另一个平台 - 在这里,新兴的机密计算硬件。 该项目更广泛的意义和重要性是加快机密计算和其他新兴计算平台的研究。 Gramine已经是100多个学术论文和几个商业产品原型的基础。 Gramine可在https://github.com/gramineproject/gramine..tramin...。该项目关注Gramine开发的三个方面。首先,该项目扩展了在Gramine上使用的系统界面和应用程序集,其目的是支持代表性Debian/Ubuntu系统上安装的90%的应用程序。其次,该项目通过解决部署问题,简化配置和策略决策,更好地与其他软件框架集成并扩展支持TEES的集合来改善Gramine用户体验。第三,通过高级测试和分析,该项目改善了Gramine代码基础的可信赖性,以及在Rust编程语言中重写关键代码。该奖项反映了NSF的法定任务,并且认为值得通过基金会的知识分子优点和更广泛的影响评估标准通过评估来获得支持。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Donald Porter其他文献
Donald Porter的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Donald Porter', 18)}}的其他基金
NSF-BSF: SaTC: CORE: Small: Rowhammering Peripherals
NSF-BSF:SaTC:核心:小型:Rowhammering 外围设备
- 批准号:
2154771 - 财政年份:2022
- 资助金额:
$ 59.84万 - 项目类别:
Standard Grant
Collaborative Research: PPoSS: Planning: Efficient Address Translation with Formal Guarantees for Data-Center-Scale Applications
协作研究:PPoSS:规划:有效的地址转换,为数据中心规模的应用程序提供正式保证
- 批准号:
2119300 - 财政年份:2021
- 资助金额:
$ 59.84万 - 项目类别:
Standard Grant
SaTC: NSF-BSF: CORE: Small: Attacking and Defending the Lifespan of Mobile and Embedded Flash Storage
SaTC:NSF-BSF:CORE:小型:攻击和捍卫移动和嵌入式闪存存储的寿命
- 批准号:
1816263 - 财政年份:2018
- 资助金额:
$ 59.84万 - 项目类别:
Standard Grant
CSR: Small: Collaborative Research: Easily Adapting Apps to Diverse Wearable Form Factors
CSR:小:协作研究:轻松调整应用程序以适应不同的可穿戴设备外形
- 批准号:
1718491 - 财政年份:2017
- 资助金额:
$ 59.84万 - 项目类别:
Standard Grant
SDI-CSCS: Collaborative Research: S2OS: Enabling Infrastructure-Wide Programmable Security with SDI
SDI-CSCS:协作研究:S2OS:通过 SDI 实现基础设施范围内的可编程安全性
- 批准号:
1700512 - 财政年份:2017
- 资助金额:
$ 59.84万 - 项目类别:
Continuing Grant
Student Travel Support for the 14th USENIX File and Storage Technologies conference (FAST 2016)
第 14 届 USENIX 文件和存储技术会议 (FAST 2016) 的学生旅行支持
- 批准号:
1600140 - 财政年份:2016
- 资助金额:
$ 59.84万 - 项目类别:
Standard Grant
CAREER: Beyond Virtual Hardware: VMM/OS Co-Design for Lightweight, Flexible Virtualization
职业:超越虚拟硬件:VMM/OS 协同设计实现轻量级、灵活的虚拟化
- 批准号:
1700810 - 财政年份:2016
- 资助金额:
$ 59.84万 - 项目类别:
Continuing Grant
TWC: Medium: Collaborative: Trustworthy Programs Without A Trustworthy Operating System
TWC:媒介:协作:无需可信操作系统的可信程序
- 批准号:
1228839 - 财政年份:2012
- 资助金额:
$ 59.84万 - 项目类别:
Standard Grant
CAREER: Beyond Virtual Hardware: VMM/OS Co-Design for Lightweight, Flexible Virtualization
职业:超越虚拟硬件:VMM/OS 协同设计实现轻量级、灵活的虚拟化
- 批准号:
1149229 - 财政年份:2012
- 资助金额:
$ 59.84万 - 项目类别:
Continuing Grant
相似国自然基金
钛基骨植入物表面电沉积镁氢涂层及其促成骨性能研究
- 批准号:52371195
- 批准年份:2023
- 资助金额:50 万元
- 项目类别:面上项目
CLMP介导Connexin45-β-catenin复合体对先天性短肠综合征的致病机制研究
- 批准号:82370525
- 批准年份:2023
- 资助金额:49 万元
- 项目类别:面上项目
人工局域表面等离激元高灵敏传感及其系统小型化的关键技术研究
- 批准号:62371132
- 批准年份:2023
- 资助金额:49 万元
- 项目类别:面上项目
优先流对中俄原油管道沿线多年冻土水热稳定性的影响机制研究
- 批准号:42301138
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
用于稳定锌负极的界面层/电解液双向调控研究
- 批准号:52302289
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
相似海外基金
Collaborative Research: SaTC: CORE: Medium: Differentially Private SQL with flexible privacy modeling, machine-checked system design, and accuracy optimization
协作研究:SaTC:核心:中:具有灵活隐私建模、机器检查系统设计和准确性优化的差异化私有 SQL
- 批准号:
2317232 - 财政年份:2024
- 资助金额:
$ 59.84万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Using Intelligent Conversational Agents to Empower Adolescents to be Resilient Against Cybergrooming
合作研究:SaTC:核心:中:使用智能会话代理使青少年能够抵御网络诱骗
- 批准号:
2330940 - 财政年份:2024
- 资助金额:
$ 59.84万 - 项目类别:
Continuing Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
- 批准号:
2338301 - 财政年份:2024
- 资助金额:
$ 59.84万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Differentially Private SQL with flexible privacy modeling, machine-checked system design, and accuracy optimization
协作研究:SaTC:核心:中:具有灵活隐私建模、机器检查系统设计和准确性优化的差异化私有 SQL
- 批准号:
2317233 - 财政年份:2024
- 资助金额:
$ 59.84万 - 项目类别:
Continuing Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
- 批准号:
2338302 - 财政年份:2024
- 资助金额:
$ 59.84万 - 项目类别:
Continuing Grant