본문

서브메뉴

Secure Systems From Insecure Components
Secure Systems From Insecure Components
Secure Systems From Insecure Components

Detailed Information

자료유형  
 학위논문 서양
최종처리일시  
20250211152045
ISBN  
9798384448426
DDC  
004
저자명  
Dauterman, Emma.
서명/저자  
Secure Systems From Insecure Components
발행사항  
[Sl] : University of California, Berkeley, 2024
발행사항  
Ann Arbor : ProQuest Dissertations & Theses, 2024
형태사항  
271 p
주기사항  
Source: Dissertations Abstracts International, Volume: 86-03, Section: B.
주기사항  
Advisor: Popa, Raluca Ada;Stoica, Ion.
학위논문주기  
Thesis (Ph.D.)--University of California, Berkeley, 2024.
초록/해제  
요약In many computer systems today, an attacker that compromises just one system component can steal many users' data. Unfortunately, past experience shows that attackers are very effective at compromising system components, whether by exploiting some software vulnerability, compromising hardware, or launching a phishing attack.In this thesis, we show how to build systems that provide strong security and privacy properties even if the individual components are insecure. This way, even if an attacker compromises any single component in the system, it cannot compromise user security and privacy. While this property is possible to achieve in theory using general-purpose cryptographic techniques, the challenge is to instantiate it efficiently in practice. The key idea is to co-design the system with the cryptography to reduce costs.We examined two core aspects of this problem: hiding queries and securing accounts. Users who store their data encrypted at servers still need to query their data. We built systems that provide both strong privacy guarantees and good concrete efficiency for keyword search (DORY), time-series analytics queries (Waldo), and object stores (Snoopy). Users also need to protect their accounts in the event of client device loss or compromise, but also in the event of service provider compromise. We built an encrypted backup system that relies on secure hardware without fully trusting it (SafetyPin) and a service that records every authentication without learning private information (larch).The Signal end-to-end encrypted messaging application uses some of the techniques in Snoopy to scale its private contact discovery service, which privately matches user contacts to Signal users.
일반주제명  
Computer science
일반주제명  
Computer engineering
일반주제명  
Information technology
키워드  
Phishing attack
키워드  
Cryptographic techniques
키워드  
Signal users
키워드  
Object stores
키워드  
DORY
기타저자  
University of California, Berkeley Computer Science
기본자료저록  
Dissertations Abstracts International. 86-03B.
전자적 위치 및 접속  
로그인 후 원문을 볼 수 있습니다.

MARC

 008250123s2024        us                              c    eng  d
■001000017162713
■00520250211152045
■006m          o    d                
■007cr#unu||||||||
■020    ▼a9798384448426
■035    ▼a(MiAaPQ)AAI31337280
■040    ▼aMiAaPQ▼cMiAaPQ
■0820  ▼a004
■1001  ▼aDauterman,  Emma.
■24510▼aSecure  Systems  From  Insecure  Components
■260    ▼a[Sl]▼bUniversity  of  California,  Berkeley▼c2024
■260  1▼aAnn  Arbor▼bProQuest  Dissertations  &  Theses▼c2024
■300    ▼a271  p
■500    ▼aSource:  Dissertations  Abstracts  International,  Volume:  86-03,  Section:  B.
■500    ▼aAdvisor:  Popa,  Raluca  Ada;Stoica,  Ion.
■5021  ▼aThesis  (Ph.D.)--University  of  California,  Berkeley,  2024.
■520    ▼aIn  many  computer  systems  today,  an  attacker  that  compromises  just  one  system  component  can  steal  many  users'  data.  Unfortunately,  past  experience  shows  that  attackers  are  very  effective  at  compromising  system  components,  whether  by  exploiting  some  software  vulnerability,  compromising  hardware,  or  launching  a  phishing  attack.In  this  thesis,  we  show  how  to  build  systems  that  provide  strong  security  and  privacy  properties  even  if  the  individual  components  are  insecure.  This  way,  even  if  an  attacker  compromises  any  single  component  in  the  system,  it  cannot  compromise  user  security  and  privacy.  While  this  property  is  possible  to  achieve  in  theory  using  general-purpose  cryptographic  techniques,  the  challenge  is  to  instantiate  it  efficiently  in  practice.  The  key  idea  is  to  co-design  the  system  with  the  cryptography  to  reduce  costs.We  examined  two  core  aspects  of  this  problem:  hiding  queries  and  securing  accounts.  Users  who  store  their  data  encrypted  at  servers  still  need  to  query  their  data.  We  built  systems  that  provide  both  strong  privacy  guarantees  and  good  concrete  efficiency  for  keyword  search  (DORY),  time-series  analytics  queries  (Waldo),  and  object  stores  (Snoopy).  Users  also  need  to  protect  their  accounts  in  the  event  of  client  device  loss  or  compromise,  but  also  in  the  event  of  service  provider  compromise.  We  built  an  encrypted  backup  system  that  relies  on  secure  hardware  without  fully  trusting  it  (SafetyPin)  and  a  service  that  records  every  authentication  without  learning  private  information  (larch).The  Signal  end-to-end  encrypted  messaging  application  uses  some  of  the  techniques  in  Snoopy  to  scale  its  private  contact  discovery  service,  which  privately  matches  user  contacts  to  Signal  users.
■590    ▼aSchool  code:  0028.
■650  4▼aComputer  science
■650  4▼aComputer  engineering
■650  4▼aInformation  technology
■653    ▼aPhishing  attack
■653    ▼aCryptographic  techniques
■653    ▼aSignal  users
■653    ▼aObject  stores
■653    ▼aDORY
■690    ▼a0984
■690    ▼a0489
■690    ▼a0464
■71020▼aUniversity  of  California,  Berkeley▼bComputer  Science.
■7730  ▼tDissertations  Abstracts  International▼g86-03B.
■790    ▼a0028
■791    ▼aPh.D.
■792    ▼a2024
■793    ▼aEnglish
■85640▼uhttp://www.riss.kr/pdu/ddodLink.do?id=T17162713▼nKERIS▼z이  자료의  원문은  한국교육학술정보원에서  제공합니다.

Preview

Export

ChatGPT Discussion

AI Recommended Related Books


    New Books MORE
    Statistics for the past 3 years. Go to brief

    detalle info

    • Reserva
    • No existe
    • Mi carpeta
    • Primera solicitud
    • Non-Book Loan Application
    • Nighttime Book Loan Application
    Material
    número de libro número de llamada Ubicación estado Prestar info
    TF11971 전자도서 대출가능 My Folder 부재도서신고 비도서대출신청 야간 도서대출신청

    * Las reservas están disponibles en el libro de préstamos. Para hacer reservaciones, haga clic en el botón de reserva

    Books borrowed together with this book

    Related Popular Books

    Available after logging in.