| Tech ID |
Title |
|
| 23222 |
Multi-level Information Security in Information Flow Tracking
Information flow tracking (IFT) is a frequently used technique for enforcing IFC. IFT associates a label with data, and monitors the propagation of this label through the system to check if sensitive data leaks to an unclassified domain or if integrity-critical components are affected by untrusted data. With more functional units, such as security primitives, being built into hardware to meet performance and power constraints, it is required that embedded security be enforced from the underlying hardware up. In this process, hardware assisted IFT methods have been deployed to capture harmful flows of information including those through hardware specific timing channels. Implicit flows resulting from these timing channels have been shown to leak secret keys in stateful elements such as caches and branch predictors. In addition, such timing flows can cause violations in real-time constraints, hindering real-time operations of a system or even rendering the critical system useless. Further, these channels are so hard to detect that they are usually identified only after operational critical security policies have been violated.Critical embedded systems such as those found in the military, industrial infrastructures and medical devices all require strict guarantees on information flow security because of the extremely high cost of a failure. These systems require rigorous design and testing to ensure that untrusted information never affects trusted computation or that secret information never leaks to unclassified domains. The requirements, for both integrity and confidentiality, can be captured by the formal model of information flow security.
(more...) |
|
| 23220 |
Eliminating Timing Information Flows in a Mix-trusted System-on-Chip
Modern computing systems continue to find themselves in control of applications which we rely on for our personal health and safety. These systems which require high-assurance have a very high cost of failure. In order to build such a system with complete security, it must be built with a secure computing foundation. Creating such a secure hardware foundation is non-trivial for a number of reasons. One of which is due to the use of third-party intellectual property cores to reduce both the cost and design time of modern system-on-chips (SOC). Ensuring the integrity of trusted cores in these systems becomes difficult since the behavior of the third party cores is undefined.
(more...) |
|
| 23001 |
Privacy Preserving Genomic Mobile Device Computational Infrastructure
With the cost of sequencing the human genome dropping exponentially it will soon be economical for individuals to get the results of paternity tests, personal medicine analyses and even genetic matching or compatibility tests without the expense or trouble of elaborate laboratory procedures. Additionally, researchers from UCI’s Genomics and Computer Science departments have developed a safe and secure methodology and infrastructure to conduct these tests, safely and securely and all done via mobile devices.
(more...) |
|
| 22931 |
Automatic Facial Expression Recognition System Using Emotion Avatar
Current facial recognition techniques are limited to analyzing the spatial and temporal information for every single frame of video. The inherent challenge for facial expression recognition and predicting human emotion is the dilemma between rigid motion of the head pose and the non-rigid motion of facial muscles. Current technology has a credible capacity to estimate head pose, however, difficulty arises estimating non-rigid motion of facial muscles with issues such as non-rigid morphing and person specific appearance.
(more...) |
|
| 21993 |
Method for Malware Detection and Classification using Image Processing Techniques
A novel method for visualizing and classifying malware using image processing techniques, applicable to malware detection and anti-virus software.
(more...) |
|
| 21959 |
Borealis : Accurate Outdoor AP Location using Smartphones
A system that provides accurate directional guidance and leads users to a desired AP after a few measurements. This solution uses off-the-shelf smartphones and produces real-time results with a small number of measurements.
(more...) |
|
| 21825 |
Method to Improve Random Number Generators
UC San Diego inventors have come up with a new method for improving pseudo-random number generators. Based on new theoretical achievements in algebraic theory of quasigroups, it can work over alphabets of n-bit letters for every n>1, and can enlarge the period of the pseudo random string of numbers and pass every known statistical test of randomness. The method is easy to implement in software or hardware in less than 1 kilobyte of memory space. The method can also be used as an improver of biased truly random number generators.
(more...) |
|
| 21364 |
Transaction Verification On Rfid-Enabled Payment And Transaction Instruments
A new method that allows users to verify the transaction details (e.g., the amount being charged) and explicitly approve them on RFID enabled payment and transaction instruments.
(more...) |
|
| 21209 |
HDRL: Homogeneous Dual-Rail Logic For DPA Attack Resistive Secure Circuit Design
HDRL (Homogeneous Dual-Rail Logic) is a standard cell level DPA (Differential Power Analysis) attack countermeasure that theoretically guarantees fully-balanced power consumption and has been shown to significantly improve the DPA attack resistivity of hardware with low energy overhead and no delay overhead over conventional countermeasures.
(more...) |
|
| 20900 |
GARM: Cross Application Data Provenance and Policy Enforcement
Current computing systems typically do not store information about the provenance or origins of the files they contain. More specifically, the information sources used to create the file is also unknown. UCI researchers have developed GARM, a new tool for tracing data provenance and enforcing data access policies with arbitrary binaries.
(more...) |
|
| 20813 |
Software And Hardware Methods For Multi-Variant Parallel Program Execution To Detect, Quarantine And Repair Malicious Code Injection
In its simplest form this invention consists of a novel software-only approach to malicious code detection and repair in real time. However by including a minute extra component (< 0.001% total transistor count) to a standard commercial processor this process can enable fully automatic repair of malicious code injections.
(more...) |
|
| 20724 |
Distributed Cryptographic System
Admission control is an essential and fundamental security service in mobile ad hoc networks (MANETs). Most previously proposed admission control protocols are prohibitively expensive and require a lot of interaction among MANET nodes. This invention presents a secure, efficient and a fully non-interactive admission control protocol for short-lived MANETs.
(more...) |
|
| 20672 |
RFID Reader Revocation Checking Using Low Power Attached Displays
A new RFID reader authentication protocol that allows efficient and timely check of revocation status of the reader’s certificate.
(more...) |
|
| 20652 |
Filtering Sources Of Unwanted Traffic
A set of algorithms that given (i) a blacklist containing the source IP addresses of unwanted traffic and (ii) a constraint on the number of filters, they construct a compact set of ranges of IP addresses that should be blocked using one filter per IP range, so as to optimize the tradeoff between the unwanted and legitimate traffic that is blocked.
(more...) |
|
| 20647 |
A Random Number Generator Based On The Spontaneous Alpha-Decay
The present invention is an apparatus and a method for generation of random numbers. The apparatus comprises an alpha-radiation source, such as Am 241, for which the decay product produces no secondary radiation with the energy equal or higher than that of the prime alpha radiation. The alpha particles emitted by the isotope and having reached the detector have a narrow energy spectrum and, hence, produce identical electrical pulses in a detector. An alpha-particle detection system is provided which includes a differential discriminator in combination with a logical selector. This combination of elements allows a positive identification of individual events of alpha-decay in the alpha-radiation source to be made and filters out any other signals produced by different radiation sources both inside and outside the apparatus. An electronic unit processes the stream of identical electric pulses into a stream of random numbers.
(more...) |
|
| 20302 |
Constant Power Design Encryption Technology
Electronic commerce, electronic banking and private networks cannot operate without a secure encryption technology. Many encryption algorithms have been developed and while secure against mathematical attacks are vulnerable to so called side-attacks. Side attacks can reveal the secret keys through information leaked by the hardware. Differential Power Analysis (DPA) is based on the fact that logic operations have power characteristics that depend on the input data. Statistical analysis of measured power traces link the switching activities of the circuit to the secret keys. Different techniques have been proposed to prevent this information leakage: interleaved dummy instructions, random power consumption, duplicate logic, etc.; however, all of these methods have eventually been circumvented.Side-channel information is leaked due to the fact that logic operations charge and discharge total nodal capacitance depending on the exact operation.
(more...) |
|
| 20243 |
Protecting Privacy From Social Network Structure-based Inference
Recent years have seen a huge growth in online social networking sites such as Facebook, Myspace, and Friendster. Given the huge amount of personal data and social relationships available in online social networks, protecting ones personal privacy is a growing problem. Since private information can be inferred via social relationships, it is possible to infer private information even when such information is not shared.
(more...) |
|
| 20225 |
Optimal Routing Protocol Secure Against Malicious Adversary
The Internet has become a ubiquitous tool in many aspects of society, yet remains surprisingly susceptible to attacks. Even a single malicious node along the pathway from sender to receiver can corrupt communication in a meaningful way. Secure routing protocols attempt to verify that packets of data are correctly delivered to their destination. However, the internet is large, heterogeneous, complex in topology, and dynamically changing. Failure localization and path-quality monitoring in the public key setting have therefore become two of the biggest challenges in communication. Current routing protocols such as link-state and distance-vector are susceptible to loops, slow convergence, oscillations, and suffer from high communication overhead. The number of network applications continues to increase, and the need for secure, dynamic routing that is resilient to malicious adversaries is evident.
(more...) |
|
| 20209 |
Differential Power Analysis Resistant Logic Style
Security chips leak information through power consumption, timing, and electro-magnetic radiation although they are secure against mathematical attacks. One of the most effective side channel attacks to the encryption ICs is the differential power analysis attack. In DPA, the attacker measures the power consumption of the chip while it encrypts and by doing a statistical analysis he can extract the secret-key. This is due to the asymmetry of the power consumption in the standard CMOS logic gates since they have power characteristic that is dependent on the input signals. Different techniques have been proposed to prevent this information leakage: interleaved dummy instructions, random power consumption, duplicate logic, etc.; however, all of these methods have been circumvented.
(more...) |
|
| 19310 |
SQUID
University researchers have written a high-performance proxy caching server for web clients, supporting FTP, gopher, and HTTP data objects. Using a single, non-blocking, I/O-driven process, Squid is able to handle all requests. For more information on the software and how it is used in academic and research settings, see the SQUID website, at http://www.squid-cache.org/
(more...) |
|
| 19304 |
Secure Internet-based Behavior Modification
The invention is a new technique for people to engage in behavior modification (smoking cessation, dieting, etc.) or explore mutual interests in a secure fashion via the Internet. A working prototype exists and is showing efficacy similar to chemical means for certain behavior modifications. Prototype exhibits the secure and interactive nature of the invention.
(more...) |
|