Opportunity: Assurance and Resilience through Zero-Trust Security
Opportunity Number:
AFRL-001
Opportunity Number:
Rome, NY
Opportunity Description:
Zero-trust cybersecurity is a security model that rigorously verifies every user and device before granting access to computing or network resources. Within cloud environments, this principle dictates that no entity, whether internal or external to commercial and public cloud systems (including the Cloud Service Provider), is trusted by default. While offering robust security, the practical implementation of zero-trust often relies on complex and resource-intensive technologies, such as public-key infrastructure and zero-knowledge proofs. This makes designing truly efficient and scalable solutions based on zero-trust a significant challenge. This research topic seeks novel approaches to: 1) enabling warfighters to efficiently and securely outsource private data and computation with mission assurance and verifiable correctness of results to untrusted commercial clouds without relying on a Trusted Third Party (TTP); 2) improving the resilience and robustness of the Air Force’s mission-critical applications by effectively distributing them across multiple heterogeneous CSPs to prevent a single point of failure, avoid technology/vendor lock-ins, and to enhance availability and survivability; 3) optimize the trade-off between strict zero-trust security and rigid performance requirements for time-sensitive mission applications. Research topics of interest include, but are not limited to: – Decentralized identity and access control mechanisms and protocols, including those that support anonymity. – Novel cryptographic primitives and protocols with application to zero-trust computing paradigms. – Design cross-cloud, CSP-independent, privacy-aware protocols and frameworks that operate in the presence of emerging zero-trust security mechanisms. – End-to-end data protection, concurrency, and consistency for multi-user multi-cloud environments. – Access patterns and volume leakage prevention for oblivious data stores under malicious security. – Verification and authentication schemes for query evaluation over encrypted and unencrypted data.
Opportunity Skill Set:
Cybersecurity; Programming languages; Machine learning (ML); Large language models (LLMs); Data analysis; Cryptography; Cloud computing; Blockchain; Computer vision; Image processing;