CRII

group_project

Visible to the public CRII: SaTC: Towards Non-Intrusive Detection of Resilient Mobile Malware and Botnet using Application Traffic Measurement

The development of the mobile Internet economy has brought numerous benefits to people and society, with the promise of providing ubiquitous computing and communications. Mobile devices have penetrated almost every aspect of our lives and, as a result, are storing a large amount of personal data.

group_project

Visible to the public CRII: SaTC: Robust and Platform Independent Recovery of Design Features from C++ Binaries

Computer software play a ubiquitous role in the modern way of life. Attacks against vulnerable software lead to compromise and loss of financial and personal information. While the application stores and the software manufacturers may strive to provide vulnerability-free software, the onus to defend against attacks and ensure integrity of one?s personal information and resources is on the end-user.

group_project

Visible to the public CRII: SaTC: Rethinking Side Channel Security on Untrusted Operating Systems

Recent advances of isolated execution technologies, especially the emergence of Intel Software Guard eXtension (SGX), revolutionize the model of computer security and empower programs with sensitive data and code to be shielded from untrusted operating systems. However, their security guarantees have not yet been thoroughly investigated against the notorious vector of information leakage side-channel attacks. It is conceivable that side-channel attacks with full control of the underlying operating system are more diverse, efficient and robust than those from unprivileged programs.

group_project

Visible to the public CRII: SaTC: Re-Envisioning Contextual Services and Mobile Privacy in the Era of Deep Learning

Deep Learning (DL)-powered personalization holds great promise to fundamentally transform the way people live, work and travel, but poses high risk to people's individual privacy. This project will address the privacy risks arising in DL-powered contextual mobile services by developing solutions that facilitate the use of personal information while maintaining explicit user control over use of the information.

group_project

Visible to the public CRII: SaTC: Privacy-Enhancing User Interfaces Based on Individualized Mental Models

Technology advances have brought numerous benefits to people and society, but also heightened risks to privacy. This project will investigate mechanisms and build tools to help people make privacy-aware decisions in different online contexts. The outcomes will help people to better understand their own privacy preferences and behavior, and enable them to better manage their privacy on the Internet. The project will create designs that can be integrated into mobile app markets and web browsers. The results will also inform Internet standards and governmental policies on Internet privacy.

group_project

Visible to the public CRII: SaTC: Hardware based Authentication and Trusted Platform Module functions (HAT) for IoTs

Crucial and critical needs of security and trust requirements are growing in all classes of applications such as in automobiles and for wearable devices. Traditional cryptographic primitives are computation-intensive and rely on secrecy of shared or session keys, applicable on large systems like servers and secure databases. This is unsuitable for embedded devices with fewer resources for realizing sufficiently strong security. This research addresses new hardware-oriented capabilities and mechanisms for protecting Internet of Things (IoT) devices.

group_project

Visible to the public CRII: SaTC: Efficient Secure Multiparty Computation of Large-Scale, Complex Protocols

Many challenging real world problems, e.g., voting and blind auction, require computation over sensitive data supplied by multiple mutually-distrustful entities. Elegant cryptographic theories have been developed to solve these problems without relying on a mutually-trusted third party. Practitioners also built prototypes capable of securely computing set intersection, AES encryption, Hamming distance, etc. However, many other applications, such as data mining and running universal machines, are far more complex than what can be supported by the state-of-the-art techniques.

group_project

Visible to the public CRII: SaTC: Computational Correlations: A New Tool for Cryptography

Understanding the computational hardness of securely realizing cryptographic primitives is a fundamental problem in cryptography. One such vital cryptographic primitive is oblivious transfer and understanding the essence of implementing it has significant consequences to cryptography, like bringing secure multi-party computation closer to reality. This research develops a new theory to explore this broad concept, namely the theory of computational correlations.

group_project

Visible to the public CRII: SaTC: Automated Proof Construction and Verification for Attribute-based Cryptography

This project develops a comprehensive proof construction and verification framework for a well-defined class of cryptographic protocols: attribute-based cryptosystems. In particular, existing automated proof construction and verification frameworks, such as EasyCrypt and CryptoVerif, are extended to provide support for attribute-based cryptography. The extensions consist of libraries of simple transformations, algebraic manipulations, commonly used abstractions and constructs, and proof strategies, which will help in generation and verification of proofs in attribute-based cryptography.