NSF Safe-OSE: Strengthening Critical Privacy Infrastructure

NSF Award Search · 01002526DB NSF RESEARCH & RELATED ACTIVIT · $1,500,000 · view on nsf.gov ↗

Abstract

This Safety, Security, and Privacy of Open-Source Ecosystems (Safe-OSE) project focuses on improving a critical piece of open-source software utilized by U.S. government agencies for national security and foreign policy purposes, by U.S.-based companies and organizations to deliver their services, and by individual citizens of the U.S. to bolster their privacy online. The project will focus on transitioning the software to a stronger form of encryption, ensuring that all users of the software are protected against evolving threats posed by quantum computing. The project will also resolve vulnerabilities posed by a variety of other threats that can compromise the safety, security, or privacy of the software’s users, including threats from outside governments, potential malicious developers who might try to inject compromised code into the software’s dependencies, and insiders that have had their accounts compromised through phishing attacks, and more. This Safe-OSE project addresses the software’s (1) potential weakness to decryption caused by its use of pre-quantum encryption algorithms and (2) potential weaknesses to socio-technical threats like supply-chain attacks, long- and short-term infiltration, foreign government compromise, and compromised infrastructure. The project will (a) convert existing threat model findings into concrete security implementation measures; (b) implement supply chain resilience for automated dependency management; (c) provide a reproducible im

Key facts

NSF award ID
2534285
Awardee
The Tor Project (NH)
SAM.gov UEI
ZFLJCT6DHBD7
PI
Micah Anderson
Primary program
01002526DB NSF RESEARCH & RELATED ACTIVIT
All programs
NETWORKING RESEARCH, Cyber Secur - Cyberinfrastruc, EXP PROG TO STIM COMP RES
Estimated total
$1,500,000
Funds obligated
$0
Transaction type
Cooperative Agreement
Period
10/01/2025 → 09/30/2027