wiki:SecureUpdates

Version 1 (modified by Christopher Small, 15 years ago) (diff)

--

Project Number

1696

Project Title

Exploiting Insecurity to Secure Software Update Systems
(a.k.a. SECUREUPDATES)

Technical Contacts

Justin Cappos <justinc@cs.washington.edu>

Participating Organizations

Computer Science and Engineering
University of Washington
Box 352350 Seattle, WA 98195-2350

GPO Liason System Engineer

Christopher Small <Christopher Small>

Scope

This proposed effort will create a framework that secures the software update systems that operate on GENI. The work will define and implement a security layer that can operate over many different application-specific installation environments, thus providing secure update functions for diverse GENI nodes and clients. The proposal plans to leverage the VM and the redirection proxy from the Million Node GENI project to support multiple platforms. The effort provides secure key management support for software update system developers, allowing software updates to be signed, validated, and distributed securely.

Current Capabilities

Milestones

Nov 15, 2009

Deliver short white paper or architecture document that explains the problem this project is attacking and outlines your solution, discussing how the work fits into GENI, what it will be used for, and how it will be used.

Dec 30, 2009

Deliver a design document for client library protection against replay and freeze attacks. Deliver a design document for the repository library protection against replay and freeze attacks.

Mar 28, 2010

Demonstrate client library implementation that protects against replay and freeze attacks for Linux. Demonstrate repository library implementation that protects against replay and freeze attacks.

May 30, 2010

Demonstrate push mechanism that provides security metadata to the repository library. Make available the code for example client software update system implementation using the client library.

Sept 30, 2010

Deliver a design document for client library selective trust delegation and key management. Deliver a design document for repository library selective trust delegation and key management.

MilestoneDate(CMU Lab: S2.a)? Short Milestone Description

Project Technical Documents

Quarterly Status Reports

due 31Dec09: 4Q09 Status Report

Spiral 2 Connectivity

Related Projects

Provisioning Service (Raven)

Attachments (9)

Download all attachments as: .zip